Splunk Search

How to restore the data lost from a lookup file that was overwritten by the outputlookup command?

poojamande
New Member

I was using one lookup file in dashboards. Mistakenly, the outputlookup command was fired and the file was overwritten by a blank file.
Is there a way to restore the data back to the .csv file.
Thanks

0 Karma

dkeck
Influencer

Hello,

I am not aware of any restore function at all. This is what backups are for.

You should be able to find the lookup file in the corresponding app.

Kind Regards

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...