Splunk Search

Why wasn't the lookup csv file replicated?

ddrillic
Ultra Champion

We created a lookup via the outputlookup command and we can see the file under $SPLUNK_HOME/etc/apps/<app name>/lookups on the SH where it was created. However, we don't see it on another SH and not via the UI interface of the lookups.

Any ideas?

Tags (2)
0 Karma

woodcock
Esteemed Legend

Replication of this sort only happens between Search Heads that are part of a Search Head Cluster. Yours clearly is not. The other way that you can do this is to manually synchronize using a cron job on each Search Head, or to use a tool like this:
https://splunkbase.splunk.com/app/574/

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...