Splunk Search

lookup file no longer being updated - how to identify how it was being updated

vincenp2
New Member

A splunk user has identified that a lookup table has not been updated for some time.

I was previously unaware of this lookup table as it had been created by someone else who no longer works on the system. I would like to investigate what script / report etc has generated and updated the lookup report previously, but I don't know where to start looking.

can anyone help guide me please with perhaps any queries or file searches that might be useful to identify what created the lookup file, and better still, what process/scrip/report was updating the lookup file?

thanks

0 Karma
1 Solution

FrankVl
Ultra Champion

Searching the _internal logs for the lookup name might give some clues (if those go back far enough).

For finding how it got updated, that would likely be a saved search, so if you have file system access on your search head(s), you could scan for savedsearches.conf files and in those search for the lookup name.

View solution in original post

0 Karma

FrankVl
Ultra Champion

Searching the _internal logs for the lookup name might give some clues (if those go back far enough).

For finding how it got updated, that would likely be a saved search, so if you have file system access on your search head(s), you could scan for savedsearches.conf files and in those search for the lookup name.

0 Karma

vincenp2
New Member

brilliant! many thanks, a trawl of savedsearches.conf has given me the info I need

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...