Hi,
I would like to import an external lookup table from a postgres DB.
What would be the best way to do this?
Thanks.
Brian
"Best" is subjective, depending on your situation. You have two clear-cut options:
There are good reasons for both. Obviously, #1 is much, much simpler but has a lower update frequency. #2 is much more complicated, because you have to write code to make it work. But, #2 has the advantage of there being effectively no delay between updating the database and seeing the changes in Splunk. Your "business" requirements here are likely to influence your decision one way or the other.
The high-level of each, with an example scripted lookup, is in the docs at http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources
Do you have an update?