- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
LukeMurphey
Champion
08-30-2017
01:29 PM
I know there is somewhere in Splunk's UI where you can have a scheduled search dump to a lookup file (without adding "outputlookup" to the search itself). However, now I cannot find it. Where is this option?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
LukeMurphey
Champion
08-30-2017
01:35 PM
This is available under the "Edit Schedule" menu option within the edit page of the search. Here is how you find it:
- Open the list of searches on the "Reports" view within the Search app
- Open the "Edit" menu for the search you want to edit
- Select "Edit Schedule"
- Fill out the schedule and click "Next"
- The option to output the results to a lookup will appear
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
LukeMurphey
Champion
08-30-2017
01:35 PM
This is available under the "Edit Schedule" menu option within the edit page of the search. Here is how you find it:
- Open the list of searches on the "Reports" view within the Search app
- Open the "Edit" menu for the search you want to edit
- Select "Edit Schedule"
- Fill out the schedule and click "Next"
- The option to output the results to a lookup will appear
