Hi, i have configured a csv lookup in splunk. Now i want to change the content of csv file so that it gets updated in splunk lookup search. Is there a way to this
Hi,
There are few ways to perform this,
|inputlookup abc.csv | <content modify search> | outputlookup abc.csv
Your <content modify search>
can be something like |eval <fieldname>=if(fieldname=="something","newvalue","oldvalue")
etc., to update field such as fieldname
values with the new content. Above logic varies based on your requirement, please check eval documentation here (https://docs.splunk.com/Documentation/Splunk/8.0.3/SearchReference/CommonEvalFunctions) Thanks. My objective over here is that i am having some static content which i am loading into the csv file and then reading it using inputlookup. After updating the content curently i have to replace the file in splunk back again.
@sudeep5689 Yes, may be 2nd option or 3rd option works for you.
If my solution helps, please mark it as answered