Splunk Search

how to add a new column to the existing lookup using lookup editor

mchoudhary
Explorer

Hi,
Can someone help me understand how to add a new column to an exisiting lookup (its a kvstore lookup) using the lookup editor app.
I can see option to add a new row but for adding a column it says on the top of the page : " Select the table to see editing options. To add a new column, select tab." but I am unable to locate any tab option

mchoudhary_0-1759766912068.png

 

Labels (1)
Tags (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

See here

https://help.splunk.com/en/splunk-cloud-platform/manage-knowledge-objects/splunk-app-for-lookup-file...

Seems like there's a known bug

Date filed Issue number Description

2025-03-18LOOKUP-304

Unable to Update KV Store Lookups in Splunk App for Lookup File Editor (v4.0.5)

 

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Wording in this instruction is quite confusing.  If I were writing the app, I'd change to


Right-click any element in the table to see row editing options.  Right-click a column header to see column editing options.




0 Karma

yuanliu
SplunkTrust
SplunkTrust

@bowesmana is correct: You currently cannot add column to KVstore-based lookup.  I am not convinced that this is a bug though.  It is more like a missing feature. (Based on UI design, new column is never included as an action despite what that in-line instruction says.  That misguided instruction, on the other hand, is a legitimate bug.  The UI should have detected the context and not mention column when the lookup is KV-store based.)

Practically speaking, you can export, delete, create a new one and repopulate based on the export.

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...