Splunk Search

Why are my additional columns in my asset lookup not showing in Splunk Web?

darlas
Communicator

Hi.

I have added a few additional columns to my asset lookup CSV, meaning in addition to the required columns. When I validate the content of the lookup, I see only the required columns and not my additional columns.

I validate with: |inputlookup assets

If I look at the CSV file at command line, it has All the columns (required plus additional).

If I look in GUI under lookup definitions, it only shows the required fields listed.

How can I get Splunk to acknowledge my additional columns?

Thanks,
Darla

0 Karma
1 Solution

darlas
Communicator

I have resolved my own issue. These additional columns came after I initially implemented the asset lookup table. I needed to reload apps from my deployment server to the search heads to get the latest data.

View solution in original post

0 Karma

darlas
Communicator

I have resolved my own issue. These additional columns came after I initially implemented the asset lookup table. I needed to reload apps from my deployment server to the search heads to get the latest data.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

If you are referring to the Assets in ES, you can't add additional fields for use in ES :

http://docs.splunk.com/Documentation/ES/4.0.1/User/AssetandIdentityCorrelation#Asset_lookup_fields

The fields allowed in an asset list are set by Enterprise Security and cannot be changed. Unsupported and nonstandard fields will be discarded. The first line of any asset file is a column header, and must list all of the asset fields.

0 Karma

somesoni2
Revered Legend

How were the new columns added, directly updating the lookup table file? Can you verify if the same copy of lookup was updated (check the full path of lookup in Settings->Lookups->Lookup table files)?

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...