You can manage a lookup table in the settings tab. You can update or write to a lookup either by uploading them or using the "| outputlookup" command. You can also do this on the backend under the directory $SPLUNK_HOME/etc/system/lookups/ , or in $SPLUNK_HOME/etc/<app_name>/lookups/ if the lookup belongs to a specific app. You can also list lookups using the REST api You can access your lookup table at the search bar using "| lookup" or "| inputlookup" Additionally you can set automatic lookups under the fields options. These will apply to a sourcetype kind at search time like how a calculated field or field extraction would work.
... View more