I know there is somewhere in Splunk's UI where you can have a scheduled search dump to a lookup file (without adding "outputlookup" to the search itself). However, now I cannot find it. Where is this option?
This is available under the "Edit Schedule" menu option within the edit page of the search. Here is how you find it:
View solution in original post