Splunk Search
Highlighted

How to write a search that will determine if a lookup file has been updated?

Communicator

How to write a search that will determine if a lookup file has been updated?

Thanks.

0 Karma
Highlighted

Re: How to write a search that will determine if a lookup file has been updated?

Motivator

Assuming you have a search that updates your lookup file, the easiest way would be to add another field last_update to your lookup entries. This way you can always tell when the respective entry has been last updated.

View solution in original post

0 Karma
Highlighted

Re: How to write a search that will determine if a lookup file has been updated?

Communicator

The lookup file has the "Last_Updated" field, but it has different timestamps associated with each record. Also, the lookup file is uploaded by the end-users.

0 Karma
Highlighted

Re: How to write a search that will determine if a lookup file has been updated?

Motivator

You can still load the lookup file and check for the latest "last_updated" field.
As far as I know there is no built-in possibility to check for a file update.

0 Karma
Highlighted

Re: How to write a search that will determine if a lookup file has been updated?

Communicator

Thanks DMohn

0 Karma