Splunk Search

Clustered search heads broke lookup tables where do I reupload the lookups?

Path Finder

Hi All,

so i clustered my search heads and added them to my index cluster. However it broke all my lookup tables. I took a backup of /opt/splunk/etc before I did this on the search head with all the lookups.

I guess my question is, is this as simple as just pasting the old lookups into the lookup /system/lookups/

IF SO, where do i do this on? the mgmt_uri? or the captain search head?

if not? can you paste a doc to follow?

0 Karma


You'll need use the deployer to distribute your lookups if you want them to replicate across the SHC.

An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...