Splunk Search

How to get that file to be replicated to the other search heads?

umd06
Engager

I have a cron job that creates a lookup file under $splunkhome$/etc/apps/search/lookups on one of the search heads. How do I get that file to be replicated to the other search heads? 

I've created a lookup definition for it and it works great the first time, but after the file's been updated. The new results are only available on the local sheard head. 

Labels (1)
0 Karma

yeahnah
Motivator

Hi @umd06 

You have not specified whether it is a search head cluster (SHC) or not.  An SHC should automatically replicate lookups between its SHC members.  If it isn't, you may have a replication issue.  Check the _internal logs for issues.

For standalone search heads, there is no auto mechanism to replicate lookups to other standalone search heads. 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...