What is the simplest way to populate a lookup table? I started creating a cronjob. However the splunk search command behaves oddly when executed from the command line. I have to CTRL-C to break the search. This does not work well with Linux Cron.
In theory, I'd like to create a (cron) job that updates a lookup table daily.
Thanks.
If you're populating a lookup table from within Splunk, why not just schedule the search in Splunk instead and use the outputlookup
command just as you would do with a separate cron job?
If you're populating a lookup table from within Splunk, why not just schedule the search in Splunk instead and use the outputlookup
command just as you would do with a separate cron job?
Thanks, I'll have to look into that.