How can I look for a list of 50+ values without typing in "foo=1 OR foo=29 OR foo=4219...".
Obviously without touching files on /opt/splunk/ anything, but as a normal file user.
I would like to load this from a file on my machine, a command something like inputcsv or inputlookup which, if I understand correctly, are restricted to looking on the Splunk server.
It is true that inputlookup
and inputcsv
use files on the Splunk server. However, power users can upload files into Splunk using the lookup capability, and therefore use these commands. You don't have to be a Splunk admin.
SPLUNK: I can't edit my own question, just submitted moments ago, because the edit Captcha is broken. Tried 10+ times, most not difficult. Safari 7.0.3 on a Mac.
I would have changed the middle to say "without touching any files on /opt/splunk, but as a normal user"/