Splunk Search

How to generate a lookup file with outputlookup in a specific app?

vishal_bandavad
Explorer

I am using | dbquery to get the lookup details and outputlookup to generate the lookup file, but it always generates under different app (either system/lookup or app/dbx/lookup). I am trying to run the query in a search from a different app, say SampleApp.

Please let me how I can create the lookup under SampleApp? or is there any config file I need to change or any command to move the file under a certain app?

0 Karma

sanjay_shrestha
Contributor
0 Karma

sanjay_shrestha
Contributor

Running your query to generate lookup fine under SampleApp might help.

0 Karma

vishal_bandavad
Explorer

I tried , but it is creating $SPLUNK_HOME$/etc/system/lookups/ instead of $SPLUNK_HOME$/etc/apps/SampleApp/lookups

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...