Hello, I would like to use a lookup csv file to add some info to some syslog data. I have several forwarders forwarding to a cluster environment and a couple of search heads. My question is where should I add the lookup file?
Thanks in advance
John
The lookup file goes on to the search head.. More details here docs.splunk.com/Documentation/Splunk/5.0/Knowledge/Addfieldsfromexternaldatasources
Thankyou for the info