Splunk Search

Contents of a Lookup Table

belka
Path Finder

Is it possible to look at the contents of a lookup table in Splunk? I can pull up the table in Excel out of the Splunk directories, but I was curious if there was a "lookup table viewer" in Splunk.

Tags (2)
0 Karma
1 Solution

somesoni2
SplunkTrust
SplunkTrust

You can issue "|inputlookup <your lookup file table name>" in the search screen to see content of your lookup table.

View solution in original post

somesoni2
SplunkTrust
SplunkTrust

You can issue "|inputlookup <your lookup file table name>" in the search screen to see content of your lookup table.

belka
Path Finder

Thanks! I had forgotten about that command.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...