Splunk Search
Highlighted

How to export/import lookups from 1 search head to another in Splunk?

New Member

I have a web environment with this situation:
I have set the lookup tables on one search head and it's working fine.

Now I want to use the same lookup table in the other search head and it is not working.

Please help me in importing the lookup table from one search head to another.

0 Karma
Highlighted

Re: How to export/import lookups from 1 search head to another in Splunk?

SplunkTrust
SplunkTrust

You can do it in multiple ways.

Just copy the lookup file and configurations files(transform) across the new search head.

OR

Export the lookup table using inputlookup command, save the results in a file and create lookup in the new search head using this file

Ref : http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Usefieldlookupstoaddinformationtoyourevent...

0 Karma
Highlighted

Re: How to export/import lookups from 1 search head to another in Splunk?

New Member

Thank u Renjith,

I am trying the command inputlookup in the following manner - tell me if this is the right option -

index=***** | inputlookup ***.csv

This pulls up nothing.

Could you provide me an example about how to do it.........

0 Karma