Splunk Search

New field added to lookup table not displaying


I'm adding a new field to an existing lookup table but it's not showing up in any searches. These are the steps I followed:

  • Added the new field to the existing lookup .csv file
  • Added the new column to the application props.conf LOOKUP
  • Restarted splunkd

The existing lookup fields are still showing up in searches, but not the new field. Am I missing a step?

csv (Dependent_Service_Call_Group is the new field)

CDB Call [CPSDRVRA] Response time:,CDB Call,Checkout,500,12000  
Standardize Address Request. Response time:,Standardize Address,Checkout,500,5000


filename = Dependent_Service_Metrics_NFR_Targets.csv


LOOKUP-Dependent_Service_Metrics_NFR_Targets = Dependent_Service_Metrics_NFR_Targets ElapsedMetricDescription AS ElapsedMetricDescription OUTPUTNEW Dependent_Service_Call AS Dependent_Service_Call Dependent_Service_Call_Group AS Dependent_Service_Call_Group Planned_Throughput AS Planned_Throughput Target_Response_Time_At_90th AS Target_Response_Time_At_90th
Tags (3)
0 Karma



There could be a number of reasons for this, including OUTPUT vs. OUTPUTNEW. Can you post a few lines of your csv, your props, and an example event?


0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...