I've read the documentation that if permissions are set to Global for a lookup that it can be accessed from within another app.
I want to be able to access the following lookup from the location below while I'm in Search and Reporting app.
/apps/splunk/etc/apps/SA-ThreatIntelligence/lookups/asn_by_cidr.csv
In Search I tried:
| inputlookup /apps/splunk/etc/apps/SA-ThreatIntelligence/lookups/asn_by_cidr.csv
But I get nothing back.
Try this:
| inputlookup asn_by_cidr.csv
I also tried that syntax as well to no avail.
Hi jkat54, I don't access to log into the search head to view the lookup on file. I actually now think the lookup file is empty, and hence producing no events. I can successfully access another lookup within SA-ThreatIntelligence.... We can close this one. thank you.
I found it to be empty in my testing too
If you open the enterprise security app and go to search drop down select search in drop down, try the same search and let me know.