Splunk Search

lookuptable folder

Federica_92
Communicator

Hi to everyone, I have a quick question.
Using the splunk framework I have create different query that produce lookuptable, a few of these are stored in search/lookups, other are stored in mynewapp/lookups, how can I say to my splunk framework to store all the lookuptable in the search/lookups folder?

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Run the search creating the lookup from the namespace of the search app.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Run the search creating the lookup from the namespace of the search app.

0 Karma

Federica_92
Communicator

Yes, the answer was " If the file doesn't exist, splunk create it in the app folder" Thank you

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma

Federica_92
Communicator

yes, but I have need to create the lookup file from the app

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...