Is it possible to look at the contents of a lookup table in Splunk? I can pull up the table in Excel out of the Splunk directories, but I was curious if there was a "lookup table viewer" in Splunk.
You can issue "|inputlookup <your lookup file table name>" in the search screen to see content of your lookup table.
"|inputlookup <your lookup file table name>"
View solution in original post
Thanks! I had forgotten about that command.