Lookup Explorer lists out an inventory of all the lookup-files, kvstores, saved-searches, and dashboards present on a Splunk searchhead. Each of these knowledge-objects is listed enriched with its inputs and outputs and as much detail as can be scraped from the REST interface and the lookup itself. For each lookup file, it shows the context, the columnnames, the rowcount, the filesize, and how old it is. It also identifies jobs and indexes connected to the lookup. This console helps Splunk admins answer the questions that come up every day, "What was the exact name of that lookup?" and "What app was it in?" and "How does it get updated?" and "Where does it get used?". With this console, admins can answer those questions in a single glance, instead of navigating and pivoting through Splunk Enterprise's multiple built-in consoles for Lookups, KV Collections, Saved Searches, Dashboards, and Jobs. The simple XML for the dashboard is an attachment embedded inside the PDF file. I cannot apologize enough for that, but this entry form only allows uploading PDF files not TXT or XML.
... View more