Splunk Search

Can we schedule Splunk to monitor a lookup?

ivar9692
Explorer

Can we schedule Splunk to monitor a lookup? I have 1 CSV file and that CSV file will be recreated everyday (not updated but totally recreated). i need the new data and compare the data to one of my index. How do i do this? Creating an index would not be good idea as there are 23 CSVs and moreover comparing 2 indexes is quite complicated. Any ideas how to solve this?

please ask if you need more info.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

maybe, check time-based lookup...
https://docs.splunk.com/Documentation/Splunk/6.5.0/Knowledge/Usefieldlookupstoaddinformationtoyourev...
Configure a time-based lookup
File-based and external lookups can also be time-based (or temporal), if the field matching depends on time information (a field in the lookup table that represents the timestamp).

To Configure a time-based lookup, select Configure time-based lookup, then specify the Name of the time field. You can also specify a strptime format for this time information and offsets for the time matching.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...