Getting Data In

Where to keep the lookup file in a clustered environment

surekhasplunk
Communicator

Hello,

We are moving from single deployment to clustered environment. 

Current scenario: for one of my dashboards i was getting the lookup file created by running a python script. using a cronjob. Since i dont want it to be indexed, i was just creating the file and placing it in the lookups folder of one of the apps where the dashboard is there. 

Now when i move to clustered environment how and where do i place the script to generate the lookup 

and where can i save the lookup file to automatically get shared in all the searh heads. 

thanks

 

Labels (2)
Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @surekhasplunk,

Since Splunk Search Head Cluster will not detect changes you make without Web UI or REST, you have two options;

1- You can create a custom search command runs your python script and than pipe to outputlookup. With this way the cluster will replicate lookup across members.  

2- Running python script on every search head with cronjob.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

surekhasplunk
Communicator

Hello @scelikok 

Thank you so much for your reply. 

for 1st point, if you could you please give an example snippet, that would be great

Thanks 

0 Karma
Get Updates on the Splunk Community!

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...