Splunk Search

download lookup table files

abhiram
Explorer

Hi,
I have some loopup table files in one of my app. Is there anyway to see the inner query of the lookup table and how to download/view the csv file ?

Tags (1)
0 Karma
1 Solution

Ayn
Legend

I don't really understand what you mean by "inner query", so I'm going to pass on that, but what you could do to see the contents of your lookup file is use the inputlookup command.

View solution in original post

0 Karma

Ayn
Legend

I don't really understand what you mean by "inner query", so I'm going to pass on that, but what you could do to see the contents of your lookup file is use the inputlookup command.

0 Karma

abhiram
Explorer

thanks for the answer ayn.
What I mean is how to exactly use lookuptable command syntax. If we use command | inputlookup testLookup , we get the results in table format. There is something search that made results to come. Also how to use lookuptable command against an existing sourcetype...can you help in syntax how to use the OUTPUT arguement with inputlookup command.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...