Splunk Search

How to find the related search of lookup file

kteng2024
Path Finder

Hi,

Below query is using the CSV, can I please know how the CSV file is being generated like whether is there any query that is generating it , etc.

| inputlookup webaccess.csv | tail 14 | reverse

0 Karma

somesoni2
Revered Legend

If you've file system access, you can search for that lookup file in $Splunk_home/etc/apps and $Splunk_home/etc/users directory (cd to that directory and grep) on your search head.

If you've sufficient access to run the | rest command, try this (run on your search head)

| rest splunk_server=local /servicesNS/-/-/saved/searches | table title eai:acl.app eai:acl.owner search | where match(search,"outputlookup\s+webaccess\.csv") 

kteng2024
Path Finder

Thank you so much and for quick reply.. your search worked and it is what i am looking for.

0 Karma

somesoni2
Revered Legend

Glad to be of help. Don't forget to close the question by accepting the answer that worked for you.

0 Karma

ddrillic
Ultra Champion

As @richgalloway said at How to create a lookup table from search

-- Take a look at the outputlookup command at outputlookup

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...