Splunk Search

Where i can update legit_domains.csv

zksvc
Contributor

Hi everyone i want to ask where can i get latest update for legit_domains.csv ?

Ask here because when i check it in lookup it says no owner, so i think it created automatically from Splunk.

zksvc_3-1724643142766.png

I know it can be update it manually, but it takes time again. it will helpfull when you can give me latest update for this .csv 

zksvc_1-1724642273285.png

 

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @zksvc ,

this lookup belongs to the ES Content Updates App, so it should be updated when you update this app.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @zksvc ,

this lookup belongs to the ES Content Updates App, so it should be updated when you update this app.

Ciao.

Giuseppe

zksvc
Contributor

Hi @gcusello Thanks for your reply when i check my "ES Content Updates" is version 4.0.0 and it available Update to 4.38.0 I have question if I update it, will it affect other use cases that have been enabled? Or will it be safe for other use cases?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @zksvc ,

I don't know which use cases you enabled, but it's possible,

but anyway, app upgrade is a normal activity in ES.

Ciao.

Giuseppe

0 Karma

zksvc
Contributor

Okay if like that, but did splunk 9.1.5 Compatible with 4.38.0 ? sorry because it's not my personal enviroment that's why i'm so careful before take action.

 

Ciao.

Zake

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @zksvc ,

version 4.38.0 is compatible with Splunk 9.1.x, 9.2.x and 9.3.x versions.

Anyway, this app mainly gives you new Use Cases and eventual correct some old use cases, it's described in the documentation.

ciao.

Giuseppe

0 Karma

zksvc
Contributor

Thankyou for all information 🍻

Hope you have a nice day sir

Ciao.

Zake

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...