Splunk Search

Why are my additional columns in my asset lookup not showing in Splunk Web?

darlas
Communicator

Hi.

I have added a few additional columns to my asset lookup CSV, meaning in addition to the required columns. When I validate the content of the lookup, I see only the required columns and not my additional columns.

I validate with: |inputlookup assets

If I look at the CSV file at command line, it has All the columns (required plus additional).

If I look in GUI under lookup definitions, it only shows the required fields listed.

How can I get Splunk to acknowledge my additional columns?

Thanks,
Darla

0 Karma
1 Solution

darlas
Communicator

I have resolved my own issue. These additional columns came after I initially implemented the asset lookup table. I needed to reload apps from my deployment server to the search heads to get the latest data.

View solution in original post

0 Karma

darlas
Communicator

I have resolved my own issue. These additional columns came after I initially implemented the asset lookup table. I needed to reload apps from my deployment server to the search heads to get the latest data.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

If you are referring to the Assets in ES, you can't add additional fields for use in ES :

http://docs.splunk.com/Documentation/ES/4.0.1/User/AssetandIdentityCorrelation#Asset_lookup_fields

The fields allowed in an asset list are set by Enterprise Security and cannot be changed. Unsupported and nonstandard fields will be discarded. The first line of any asset file is a column header, and must list all of the asset fields.

0 Karma

somesoni2
Revered Legend

How were the new columns added, directly updating the lookup table file? Can you verify if the same copy of lookup was updated (check the full path of lookup in Settings->Lookups->Lookup table files)?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...