Splunk Search

How to upload a lookup file to a Splunk Cloud "staging area" or through REST API?

jfgomez0912
Explorer

Hi,

In order to automate the deployment pipeline of Splunk Apps into different instances, our team has the requirement of uploading the lookups in our development environment (Splunk enterprise on-premise) to our production environment (Splunk Cloud) automatically.

After reading the Splunk REST API documentation, we encountered a way to move any file from a staging area to the lookups stored in the apps as follows:

https://host:mPort/services/data/lookup-table-files/{name}
POST
Modify a lookup table file by replacing it with a file from the upload staging area.

In order to get this type of automation, is there any way to upload a file to a Splunk Cloud "staging area", or is there any possibility to upload lookup via REST API to Splunk Cloud?

Thanks.

Labels (1)

danan5
Path Finder

Hi,

Did you ever find a way to programmatically upload to the staging area?

Regards,

0 Karma

chartastic
Explorer

Last I heard from support on the subject, this was not currently possible. Though this was July 2020 or so.

Get Updates on the Splunk Community!

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...