Splunk Search

Can we schedule Splunk to monitor a lookup?

ivar9692
Explorer

Can we schedule Splunk to monitor a lookup? I have 1 CSV file and that CSV file will be recreated everyday (not updated but totally recreated). i need the new data and compare the data to one of my index. How do i do this? Creating an index would not be good idea as there are 23 CSVs and moreover comparing 2 indexes is quite complicated. Any ideas how to solve this?

please ask if you need more info.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

maybe, check time-based lookup...
https://docs.splunk.com/Documentation/Splunk/6.5.0/Knowledge/Usefieldlookupstoaddinformationtoyourev...
Configure a time-based lookup
File-based and external lookups can also be time-based (or temporal), if the field matching depends on time information (a field in the lookup table that represents the timestamp).

To Configure a time-based lookup, select Configure time-based lookup, then specify the Name of the time field. You can also specify a strptime format for this time information and offsets for the time matching.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...