Splunk Search

How to get that file to be replicated to the other search heads?

umd06
Engager

I have a cron job that creates a lookup file under $splunkhome$/etc/apps/search/lookups on one of the search heads. How do I get that file to be replicated to the other search heads? 

I've created a lookup definition for it and it works great the first time, but after the file's been updated. The new results are only available on the local sheard head. 

Labels (1)
0 Karma

yeahnah
Motivator

Hi @umd06 

You have not specified whether it is a search head cluster (SHC) or not.  An SHC should automatically replicate lookups between its SHC members.  If it isn't, you may have a replication issue.  Check the _internal logs for issues.

For standalone search heads, there is no auto mechanism to replicate lookups to other standalone search heads. 

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...