Splunk Search

how to add a new column to the existing lookup using lookup editor

mchoudhary
Explorer

Hi,
Can someone help me understand how to add a new column to an exisiting lookup (its a kvstore lookup) using the lookup editor app.
I can see option to add a new row but for adding a column it says on the top of the page : " Select the table to see editing options. To add a new column, select tab." but I am unable to locate any tab option

mchoudhary_0-1759766912068.png

 

Labels (1)
Tags (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

See here

https://help.splunk.com/en/splunk-cloud-platform/manage-knowledge-objects/splunk-app-for-lookup-file...

Seems like there's a known bug

Date filed Issue number Description

2025-03-18LOOKUP-304

Unable to Update KV Store Lookups in Splunk App for Lookup File Editor (v4.0.5)

 

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Wording in this instruction is quite confusing.  If I were writing the app, I'd change to


Right-click any element in the table to see row editing options.  Right-click a column header to see column editing options.




0 Karma

yuanliu
SplunkTrust
SplunkTrust

@bowesmana is correct: You currently cannot add column to KVstore-based lookup.  I am not convinced that this is a bug though.  It is more like a missing feature. (Based on UI design, new column is never included as an action despite what that in-line instruction says.  That misguided instruction, on the other hand, is a legitimate bug.  The UI should have detected the context and not mention column when the lookup is KV-store based.)

Practically speaking, you can export, delete, create a new one and repopulate based on the export.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...