...pecific set of users. The problem is that there are about 130 users and I tried specifying the users in the search using (Account_Name=user1 OR Account_Name=user2 OR Account_Name=user3.......) I t...
I try to edit lookup file through the lookup file editor, but below message is shown. The file is too big to be edited (must be less than 10 MB) Is there any workaround other than reducing the lookup...
Greetings. I am quite new to Splunk and read a lot of sources. However, I have a hard time to find my answer about the join and eval functions. I have a first search on an index. I want to f...
Please tell me about the lookup operation. 1. when you register a new lookup table file (CSV) from the GUI, you can immediately refer to it on the search screen. | inputlookup “lookup.csv...
I am seeing the following alert on the Searching and Reporting App and also within the InfoSec App for Splunk. [idx-1,idx-2,sh-2] Could not load lookup=LOOKUP-threatprotect-severity I am not sure h...
Hi,
As asked in the subject I trying to figure out the difference between lookup input lookup because I don't think I get it.
in this research for example:
&n...
...itre_data_sources.csv` lookup located at `$SPLUNK_HOME/etc/apps/Splunk_Security_Essentials/lookups/mitre_data_sources.csv` ## Clean Install - First 5 Id Name Data_Source Description Data_Component D...
KV store lookups are failing with the following error:
Error in 'inputlookup' command: External command based lookup 'kvstore_lookup' is not available because KV Store initialization has failed....
I've got a question aboutlookup tables, and how to audit them. I have a rather large lookup table that's being recreated daily from a scheduled correlation search. I don't know if any other c...