Hi, I'm trying to get wildcard lookups to work using the "lookup" function. I've followed guidance to set up the "Match Type" for the fieldin the lookupdefinition as per DefineaCSVlookupinSplunk...
...enerates the output file.
My question is, how do I get the lookup table to update automatically whenever a new file is placed in the specified location?
If I definealookup using the Web GUI, would t...
Hi
I have separate machines for a Search Head and Indexer. InSplunkWeb on the Search Head, I went through the different steps as shown in the Splunk tutorial to defineautomatic lookup based o...
I have alookup table as below
User IsMember
user1 Yes
user2 Yes
user3 No
I save the table as memberlist.csv save as type is CSV(comma delimited)(*.csv)
I import the table and define...
Hi, so my team is currently has some data on Splunk cloud. My task is to use your REST API to get this data using python.
On Splunkweb I get this data by using the following query:
&n...
...earch index=* src_ip=* followed by the lookup. I added the lookup file and lookupdefinition but when I run a search it fails saying the lookup table doesnt exist.
Hello Splunkers! We have a situation here and need your help and experience. We are looking for best practice to work with Large CSV files (1Million Rows at least) to produce fast searches a...
We need to run the same query over a list of values (10k to 100k) without knowing the exact key across various indexes where they might show up. What's the best way to do this ina scalable w...
...ooling, etc).
For .csv files that I want to index (so that all search heads can get to the data), where should I upload the files? I typically use the WebUI to upload these types of files, so s...
I'm seeing the error below under messages in my Splunk enterprise console:
Missing or malformed messages.conf stanza for TCPOUT:FORWARDING_BLOCKED_Indexer IP ADDress_default-autolb-group DC-Host N...