hi, i have already uploaded a csv lookup file to the splunk indexer. Now i want to add more entries to the csv file. i goto the destination where it is stored on the indexer and open it and edit and save it and restart splunk. then from my web interface if i do a | input lookup
Thanks in Advance!!!
Hi,
Lookup tables are typically stored at the search head and not the indexer. Is this an indexer & search head instance (i.e. doing both?)
You can verify lookups from the search head by going under the Manager -> Lookups ad see where you file is listed and can verify the file contents by logging into the box and taking a look at that path.
@Kate