Splunk Search

How to export/import lookups from 1 search head to another in Splunk?

pradyprakhar
New Member

I have a web environment with this situation:
I have set the lookup tables on one search head and it's working fine.

Now I want to use the same lookup table in the other search head and it is not working.

Please help me in importing the lookup table from one search head to another.

0 Karma

renjith_nair
Legend

You can do it in multiple ways.

Just copy the lookup file and configurations files(transform) across the new search head.

OR

Export the lookup table using inputlookup command, save the results in a file and create lookup in the new search head using this file

Ref : http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Usefieldlookupstoaddinformationtoyourevent...

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

pradyprakhar
New Member

Thank u Renjith,

I am trying the command inputlookup in the following manner - tell me if this is the right option -

index=***** | inputlookup ***.csv

This pulls up nothing.

Could you provide me an example about how to do it.........

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...