Splunk Search

How to update the lookup table dynamically?

Path Finder

I have a list of hosts in the lookup table. These values aren't static and gets updated dynamically every three months. Is it possible to update the lookup dynamically in the below mentioned two ways, without updating the values manually.

1. Old values needs to be replaced by new values
2. New values should be appended to the old values in the table


Labels (1)
0 Karma


Hi @innoce,

as @ITWhisperer said, it's possible to update your hosts list using the outputlookup value in a search that takes values from the events and from the lookup.

Only one question: what to do with values in the lookup that aren't more present? do you want to list?

Anyway, please try something like this (if the lookup is named "perimeter.csv"):

| metasearch index=<your_index>
| eval host=lower(host), status="events"
| append [ | inputlookup perimeter.csv | eval host=lower(host), status="lookup" | fields host status ]
| stats 
   dc(status) AS status_count 
   values(status) AS status
   BY host
| eval Status=case(status_count=2,"Host present both in Events and Lookup", case status="events","New host present only in Events",status="lookup","Old host present only in Lookup")
| table host Status
| outputlookup perimeter.csv



0 Karma


The outputlookup command can be used to update the lookup with the results of a search.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...