Splunk Search

How to find the related search of lookup file

kteng2024
Path Finder

Hi,

Below query is using the CSV, can I please know how the CSV file is being generated like whether is there any query that is generating it , etc.

| inputlookup webaccess.csv | tail 14 | reverse

0 Karma

somesoni2
Revered Legend

If you've file system access, you can search for that lookup file in $Splunk_home/etc/apps and $Splunk_home/etc/users directory (cd to that directory and grep) on your search head.

If you've sufficient access to run the | rest command, try this (run on your search head)

| rest splunk_server=local /servicesNS/-/-/saved/searches | table title eai:acl.app eai:acl.owner search | where match(search,"outputlookup\s+webaccess\.csv") 

kteng2024
Path Finder

Thank you so much and for quick reply.. your search worked and it is what i am looking for.

0 Karma

somesoni2
Revered Legend

Glad to be of help. Don't forget to close the question by accepting the answer that worked for you.

0 Karma

ddrillic
Ultra Champion

As @richgalloway said at How to create a lookup table from search

-- Take a look at the outputlookup command at outputlookup

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...