Splunk Search

How to get that file to be replicated to the other search heads?

umd06
Engager

I have a cron job that creates a lookup file under $splunkhome$/etc/apps/search/lookups on one of the search heads. How do I get that file to be replicated to the other search heads? 

I've created a lookup definition for it and it works great the first time, but after the file's been updated. The new results are only available on the local sheard head. 

Labels (1)
0 Karma

yeahnah
Motivator

Hi @umd06 

You have not specified whether it is a search head cluster (SHC) or not.  An SHC should automatically replicate lookups between its SHC members.  If it isn't, you may have a replication issue.  Check the _internal logs for issues.

For standalone search heads, there is no auto mechanism to replicate lookups to other standalone search heads. 

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...