A knowledge object that provides data enrichment by mapping a select value in an event to a field in another data source, and appending the matched results to the original event. For example, you can use a lookup to match an HTTP status code and return a new field containing a detailed description of the status. The data sources for lookup content include search results, .csv files, geospatial .kmz files, KVStore collections, and script-facilitated external database connections.

CSV lookup files and CSV lookup definitions are also dataset types. The Datasets listing page lists them alongside data model datasets and table datasets.

Lookups are incorporated into dashboards and forms to provide content in a human readable format, allowing users to interact with event data without knowing obscure or cryptic event fields.

For more information

In the Knowledge Manager Manual:

In the Developing Views and Apps for Splunk Web: