Splunk Search

How to export/import lookups from 1 search head to another in Splunk?

pradyprakhar
New Member

I have a web environment with this situation:
I have set the lookup tables on one search head and it's working fine.

Now I want to use the same lookup table in the other search head and it is not working.

Please help me in importing the lookup table from one search head to another.

0 Karma

renjith_nair
Legend

You can do it in multiple ways.

Just copy the lookup file and configurations files(transform) across the new search head.

OR

Export the lookup table using inputlookup command, save the results in a file and create lookup in the new search head using this file

Ref : http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Usefieldlookupstoaddinformationtoyourevent...

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

pradyprakhar
New Member

Thank u Renjith,

I am trying the command inputlookup in the following manner - tell me if this is the right option -

index=***** | inputlookup ***.csv

This pulls up nothing.

Could you provide me an example about how to do it.........

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...