Splunk Search

Why are my additional columns in my asset lookup not showing in Splunk Web?

darlas
Communicator

Hi.

I have added a few additional columns to my asset lookup CSV, meaning in addition to the required columns. When I validate the content of the lookup, I see only the required columns and not my additional columns.

I validate with: |inputlookup assets

If I look at the CSV file at command line, it has All the columns (required plus additional).

If I look in GUI under lookup definitions, it only shows the required fields listed.

How can I get Splunk to acknowledge my additional columns?

Thanks,
Darla

0 Karma
1 Solution

darlas
Communicator

I have resolved my own issue. These additional columns came after I initially implemented the asset lookup table. I needed to reload apps from my deployment server to the search heads to get the latest data.

View solution in original post

0 Karma

darlas
Communicator

I have resolved my own issue. These additional columns came after I initially implemented the asset lookup table. I needed to reload apps from my deployment server to the search heads to get the latest data.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

If you are referring to the Assets in ES, you can't add additional fields for use in ES :

http://docs.splunk.com/Documentation/ES/4.0.1/User/AssetandIdentityCorrelation#Asset_lookup_fields

The fields allowed in an asset list are set by Enterprise Security and cannot be changed. Unsupported and nonstandard fields will be discarded. The first line of any asset file is a column header, and must list all of the asset fields.

0 Karma

somesoni2
Revered Legend

How were the new columns added, directly updating the lookup table file? Can you verify if the same copy of lookup was updated (check the full path of lookup in Settings->Lookups->Lookup table files)?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...