Hi.
I have added a few additional columns to my asset lookup CSV, meaning in addition to the required columns. When I validate the content of the lookup, I see only the required columns and not my additional columns.
I validate with: |inputlookup assets
If I look at the CSV file at command line, it has All the columns (required plus additional).
If I look in GUI under lookup definitions, it only shows the required fields listed.
How can I get Splunk to acknowledge my additional columns?
Thanks,
Darla
I have resolved my own issue. These additional columns came after I initially implemented the asset lookup table. I needed to reload apps from my deployment server to the search heads to get the latest data.
I have resolved my own issue. These additional columns came after I initially implemented the asset lookup table. I needed to reload apps from my deployment server to the search heads to get the latest data.
If you are referring to the Assets in ES, you can't add additional fields for use in ES :
http://docs.splunk.com/Documentation/ES/4.0.1/User/AssetandIdentityCorrelation#Asset_lookup_fields
The fields allowed in an asset list are set by Enterprise Security and cannot be changed. Unsupported and nonstandard fields will be discarded. The first line of any asset file is a column header, and must list all of the asset fields.
How were the new columns added, directly updating the lookup table file? Can you verify if the same copy of lookup was updated (check the full path of lookup in Settings->Lookups->Lookup table files)?