I am using | dbquery
to get the lookup details and outputlookup to generate the lookup file, but it always generates under different app (either system/lookup or app/dbx/lookup). I am trying to run the query in a search from a different app, say SampleApp.
Please let me how I can create the lookup under SampleApp? or is there any config file I need to change or any command to move the file under a certain app?
You can try using createinapp
option.
http://docs.splunk.com/Documentation/Splunk/6.2.1/SearchReference/Outputlookup
Running your query to generate lookup fine under SampleApp might help.
I tried , but it is creating $SPLUNK_HOME$/etc/system/lookups/ instead of $SPLUNK_HOME$/etc/apps/SampleApp/lookups