Splunk Search

How to update a lookup file in Splunk from Phantom?

yadavameeth
Engager

How to update a lookup file in splunk from Phantom?

Labels (1)
Tags (1)

mthcht
Explorer

Hi i made these scripts to update or upload lookups on splunk using lookup-editor endpoint 

It can save the content of lookup(s) from splunk, add new fields and values or merge files and update them on splunk, you can use them in your playbooks

0 Karma

MuS
Legend

Okay, found the solution! 

It's not documented anywhere but the lookup definition in Splunk needs to be shared globally AND the owner of the lookup definition needs to be 'nobody' - also remember to set the permission of the CSV so everyone is able to write and share it globally as well. 

Hope this helps ...

cheers, MuS

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You could also simply call REST API to update lookup contents.

0 Karma

MuS
Legend

That did also not work for the same permission related reasons, but like I said it's working now.

cheers, MuS

0 Karma

MuS
Legend

Hi there,

we encountered the exact same problem. Using the provided commands in the Splunk app in Phantom it seems there is no way to update a lookup table BUT we have a workaround for that 😉 If you are forwarding the Phantom event to Splunk you can use those events and run a scheduled search that will then update the lookup file.

Hope this helps ...

cheers, MuS

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...