Splunk Search

Is there any other way other than the Lookup Editor to edit and manage lookup files?

jvmerilla
Path Finder

Hello All,

I was wondering if there's a way to manage lookup files in Splunk.

What I want to do is to create/upload lookup files in Splunk and have this files saved in a location, if possible outside Splunk. And then when this lookup file get updated, it will save a new version in this location, without overwriting the old one. But in Splunk, only the updated version will remain.

I hope I make myself clear with this. 🙂

Hoping someone could help me with this.

Thanks in advance!

0 Karma

HiroshiSatoh
Champion

If it is realized only by the function of Splunk, there is a way to monitor the LOOKUP file by the Splunk server itself and acquire all the items when there is a change. You need to make sure that the beginning of the file changes.

I think that it becomes self-made such as a shell script etc. except.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...