Splunk Search

How to find the related search of lookup file

kteng2024
Path Finder

Hi,

Below query is using the CSV, can I please know how the CSV file is being generated like whether is there any query that is generating it , etc.

| inputlookup webaccess.csv | tail 14 | reverse

0 Karma

somesoni2
Revered Legend

If you've file system access, you can search for that lookup file in $Splunk_home/etc/apps and $Splunk_home/etc/users directory (cd to that directory and grep) on your search head.

If you've sufficient access to run the | rest command, try this (run on your search head)

| rest splunk_server=local /servicesNS/-/-/saved/searches | table title eai:acl.app eai:acl.owner search | where match(search,"outputlookup\s+webaccess\.csv") 

kteng2024
Path Finder

Thank you so much and for quick reply.. your search worked and it is what i am looking for.

0 Karma

somesoni2
Revered Legend

Glad to be of help. Don't forget to close the question by accepting the answer that worked for you.

0 Karma

ddrillic
Ultra Champion

As @richgalloway said at How to create a lookup table from search

-- Take a look at the outputlookup command at outputlookup

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.