I'm trying to automatize a task that consists in the topics:
-Clean eventdata from Splunk (Done)
-Upload CSV file to replace the data of old version of the file
-show dashboard(Done)
Is it possible to do the 2nd phase through the command line?
Thanks and regards
csv lookups exists in each of the apps "lookups" directory. This is a dynamic directory and it is just matter of copying to this directory
Depends on the complexity of your Splunk Installation
I use "rsync" in Linux to copy the lookup files, so it updates only when there is a change to file.
The oneshot
command may be what you're looking for. Check out http://docs.splunk.com/Documentation/Splunk/6.5.1/Data/MonitorfilesanddirectoriesusingtheCLI.