Hi All, The Bloodhound TA creates a KV store lookup. I've been asked to take the entries in the KV store and turn them into events. I've setup an alert, but I'm not seeing the alert fire...
Hi, I want to rename the fields while writing to a lookup table using outputlookup command. Is there a way to do it? I intend to use the lookup table in the next run of the same query so want s...
Hello, How to outputlookup csv with permission? ***Note that I am not Splunk admin - I only have access to Splunk GUI*** Please help. Thank you so much For example:&n...
Hello Gurus,
I'm trying to generate a lookup from a search using the outputlookup option but running into some issues.
My search returns between 400 & 500 results on the Statistics tab, b...
...ommand to get new records in last 24hrs
| bunnch of evals to format data
| append
[| inputlookup MispKVstore]
| dedup
| outputlookup append=false MispKVstore We have this running 3...
Could anyone tell me the difference between outputlookup and outputcsv?
If there no differences, is there any specifications to use the above in various circumstances?
Regards,
Naga
Does anyone know how the outputlookup command is configured? commands.conf does not reference a python script for it. I want to change how new files are created so that they are private and a...
Does the outputlookup command overwrite or append to the existing specified lookup file? The documentation does not clarify: http://www.splunk.com/base/Documentation/latest/SearchReference/Outputlookup...
...rite the new email addresses to another lookup. The issue I have is that I get duplicates as this search runs once a week. Is there a way I can avoid duplicates using outputlookup? Dedup i...
...erfect in search, so I appended a: | outputlookup file.csv to the very bottom so it'd write to a reusable csv. When I look at the dataset/csv it is rearranging my columns into an alphabetical o...