Splunk Search

csv file usage

shrinivaskittur
Explorer

Hi,

I need help in evaluation the csv files under "<Splunk directory>\etc\apps\search\lookups" folder. we have multiple csv files in this folder and I need to check which csv file is not in use or used for which search so that unused csv file can be deleted.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have access to the search head's file system then use grep to search $SPLUNK_HOME/etc/apps/*/local/savedsearches.conf and $SPLUNK_HOME/etc/apps/*/local/transforms.conf for instances of each CSV file name.  Files not referenced are not used.

In case you missed a reference to a CSV, move it temporarily to a different directory so it can be replaced if later found to be needed.

---
If this reply helps you, Karma would be appreciated.
0 Karma

shrinivaskittur
Explorer

thank you, but how do I check this on windows based search heads.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I use Ubuntu for Windows.  You also can use PowerShell

Select-string -Pattern "<text>"  <filepattern> -Simplematch
---
If this reply helps you, Karma would be appreciated.
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you not use file explorer and list the date accessed information?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...