Splunk Search

csv file usage

shrinivaskittur
Explorer

Hi,

I need help in evaluation the csv files under "<Splunk directory>\etc\apps\search\lookups" folder. we have multiple csv files in this folder and I need to check which csv file is not in use or used for which search so that unused csv file can be deleted.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have access to the search head's file system then use grep to search $SPLUNK_HOME/etc/apps/*/local/savedsearches.conf and $SPLUNK_HOME/etc/apps/*/local/transforms.conf for instances of each CSV file name.  Files not referenced are not used.

In case you missed a reference to a CSV, move it temporarily to a different directory so it can be replaced if later found to be needed.

---
If this reply helps you, Karma would be appreciated.
0 Karma

shrinivaskittur
Explorer

thank you, but how do I check this on windows based search heads.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I use Ubuntu for Windows.  You also can use PowerShell

Select-string -Pattern "<text>"  <filepattern> -Simplematch
---
If this reply helps you, Karma would be appreciated.
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Can you not use file explorer and list the date accessed information?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...