Splunk Search

lookuptable folder

Federica_92
Communicator

Hi to everyone, I have a quick question.
Using the splunk framework I have create different query that produce lookuptable, a few of these are stored in search/lookups, other are stored in mynewapp/lookups, how can I say to my splunk framework to store all the lookuptable in the search/lookups folder?

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Run the search creating the lookup from the namespace of the search app.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Run the search creating the lookup from the namespace of the search app.

0 Karma

Federica_92
Communicator

Yes, the answer was " If the file doesn't exist, splunk create it in the app folder" Thank you

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma

Federica_92
Communicator

yes, but I have need to create the lookup file from the app

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...