Splunk Search

How to update the lookup table before the scheduled search runs so it gives all lookup entries?

Nam7Splnk
Explorer

I have scheduled search that periodically updates lookup table CSV file every 15 minutes. I updated this lookup with below search query before scheduled search runs.

| inputlookup lookuptable1 | outputlookup lookuptable2 append=true 

I am able to see lookup table entries until the next time for the scheduled search but once scheduled search runs, all my new lookup entries from above search are gone.

I tried this on Standalone Search Head as well as SH cluster and the behavior is the same.

Any idea how to update this lookup table?

0 Karma
1 Solution

Nam7Splnk
Explorer

Never mind. i found issue. there was dedup condition on one field and i forgot to specify
so every time when scheduled search ran, wiped out new fields with same (empty) value.

View solution in original post

0 Karma

Nam7Splnk
Explorer

Never mind. i found issue. there was dedup condition on one field and i forgot to specify
so every time when scheduled search ran, wiped out new fields with same (empty) value.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...