i was searching for the similar issue and after reading this solution i assumed the current Splunk version also works similar to this solution. Then i was reading the docs and learnt the new options available, so i thought to update other readers who may face similar situation like myself. Until Splunk 6.5, the scheduled reports never had "Write to a CSV lookup file" option. Ref: https://docs.splunk.com/Documentation/Splunk/6.5.0/Report/Schedulereports From Splunk 6.6, the scheduled reports are having a "Write to a CSV lookup file" option. Ref: https://docs.splunk.com/Documentation/Splunk/6.6.0/Report/Schedulereports#Define_a_Write_to_a_CSV_Lookup_File_action so, if we are using Splunk 6.6 or newer versions, then, simply with scheduled reports, we can "append" the lookup files. thanks. (PS - i have given around 500+ karma points so far, received badge for that, if an answer helped you, a karma point would be nice!. we all should start "Learn, Give Back, Have Fun")
... View more