Splunk Search

How to export/import lookups from 1 search head to another in Splunk?

pradyprakhar
New Member

I have a web environment with this situation:
I have set the lookup tables on one search head and it's working fine.

Now I want to use the same lookup table in the other search head and it is not working.

Please help me in importing the lookup table from one search head to another.

0 Karma

renjith_nair
Legend

You can do it in multiple ways.

Just copy the lookup file and configurations files(transform) across the new search head.

OR

Export the lookup table using inputlookup command, save the results in a file and create lookup in the new search head using this file

Ref : http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Usefieldlookupstoaddinformationtoyourevent...

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

pradyprakhar
New Member

Thank u Renjith,

I am trying the command inputlookup in the following manner - tell me if this is the right option -

index=***** | inputlookup ***.csv

This pulls up nothing.

Could you provide me an example about how to do it.........

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...