I have a web environment with this situation:
I have set the lookup tables on one search head and it's working fine.
Now I want to use the same lookup table in the other search head and it is not working.
Please help me in importing the lookup table from one search head to another.
You can do it in multiple ways.
Just copy the lookup file and configurations files(transform) across the new search head.
Export the lookup table using inputlookup command, save the results in a file and create lookup in the new search head using this file
Ref : http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Usefieldlookupstoaddinformationtoyourevent...
Thank u Renjith,
I am trying the command inputlookup in the following manner - tell me if this is the right option -
index=***** | inputlookup ***.csv
This pulls up nothing.
Could you provide me an example about how to do it.........