Splunk Search

How to export/import lookups from 1 search head to another in Splunk?

pradyprakhar
New Member

I have a web environment with this situation:
I have set the lookup tables on one search head and it's working fine.

Now I want to use the same lookup table in the other search head and it is not working.

Please help me in importing the lookup table from one search head to another.

0 Karma

renjith_nair
Legend

You can do it in multiple ways.

Just copy the lookup file and configurations files(transform) across the new search head.

OR

Export the lookup table using inputlookup command, save the results in a file and create lookup in the new search head using this file

Ref : http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Usefieldlookupstoaddinformationtoyourevent...

Happy Splunking!
0 Karma

pradyprakhar
New Member

Thank u Renjith,

I am trying the command inputlookup in the following manner - tell me if this is the right option -

index=***** | inputlookup ***.csv

This pulls up nothing.

Could you provide me an example about how to do it.........

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...