Splunk Search

If a user adds a CSV input as lookup, is it the same as an administrator's ability to upload and "add data"?

dxw350
Path Finder

Will the search and results be the same if a user or power user adds a CSV file as a lookup file compared to the administrators ability to "add data" or is there an advantage to having my administrator upload. The file data and fields will only be used in one particular app.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

There are two different things to understand out of this...

1) Uploading a CSV file as lookup
2) Add Data

These are two different functions.

Add Data will actually allow you to apply a sourcetype, linebreaking, timestamp recognition etc, and then the data will get indexed into the specified index in Splunk. So this is indexing data.

Uploading a CSV does not index data, apply sourcetypes, linebreaking etc. It's only applied as a lookup file. For the matter of this article, lookups are not indexed. They are knowledge objects that are available to be applied either as an autolookup per a sourcetype, or for data enrichment via the lookup command.

How you would join the indexed data vs a lookup are also different.

Which one is best, depends on your use case... Lookups are temporal, so they are easy to update and maintain. When you have a 'lookup' that is indexed, then you have to consider that in your searches for joining on the most recent or accurate data...

0 Karma

adonio
Ultra Champion

when indexing the data, timestamps will be added to the csv events
therefore, when searching, you will slowly have to increase your time range
when using a lookup, there is no timestamp attached to events
another consideration might be, who needs access to this data? when indexing, you can control permissions by index.
one last that comes to mind is how big is the lookup? if its very large, you will probably lean toward indexing the data
what is the use case for this csv file?
hope it helps

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...