Splunk Search

Can we update a lookup CSV file through a URL in splunk

skhan28
Explorer

I have CSV inventory  file which is dynamic and same needs to updated in splunk manually, Is there a way  to integrate the URL  with splunk  to update lookup file 

Labels (1)
Tags (1)
0 Karma
1 Solution

skhan28
Explorer

Thanks @inventsekar for the solution, but we are using splunk cloud which is managed by Splunk so  will they  allow us to perform these steps in splunk server, Will they grant us access for splunk cloud 

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @skhan28 .. i assume that the inventory file is dynamic and you are manually loading this file to splunk and using it as a lookup file.

to avoid the manual file uploading, you can create the file directly at the lookup files location(thru some script or the application which creates the file can save/send to this path )

$SPLUNK_HOME\etc\apps\<yourApp>\lookups\lookup-name.csv

once its done, you can use the "lookup" or "inputlookup" commands

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

skhan28
Explorer

Thanks @inventsekar for the solution, but we are using splunk cloud which is managed by Splunk so  will they  allow us to perform these steps in splunk server, Will they grant us access for splunk cloud 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @skhan28 As per my understanding, Splunk Cloud is managed by Splunk Guys and we can not get access to those systems. 

but, you can work with Splunk Support and send the csv files to the correct location(thru some scripting or thru some methods which Splunk Support suggests).

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

skhan28
Explorer

Sure @inventsekar ,  Thanks for the solution, I'll check with splunk support for access 

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...