Splunk® App for Lookup File Editing

User Guide

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

About the Splunk App for Lookup File Editing

Use the Splunk App for Lookup File Editing to easily add and edit lookup files within the Splunk platform. This app provides an Excel-like user interface for importing, editing, and exporting both KV store and CSV-based lookup files.

The Splunk App for Lookup File Editing offers the following features:

  • Manage lookup files entirely within Splunk
  • Import CSV files into a lookup
  • Import KV store data into a lookup
  • Edit lookups within a GUI similar to Excel
  • View or restore lookups using revision history

The Splunk App for Lookup File Editing also enables your lookups to work on search head cluster environments. Any edits made to lookups are propagated to your other search heads.

This image shows an example of a populated screen of the Splunk App for Lookup File Editing. The interface resembles a spreadsheet with columns and rows to capture the name, type, and other details on each file listed. Options to filter the view are available.


Install the Splunk App for Lookup File Editing

Download the Splunk App for Lookup File Editing from Splunkbase. The Splunk App for Lookup File Editing is compatible with Splunk Enterprise versions 8.1.9 and 8.2.6, or Splunk Cloud Platform.

This app does not require any configuration. You can just install the app using the Splunk Apps Manager:

  1. Log in to Splunk Web and go to Apps > Manage Apps.
  2. Click Install app from file.
  3. Choose the downloaded app file and click Upload.
Last modified on 16 May, 2022
  NEXT
Navigate and use the Splunk App for Lookup File Editing

This documentation applies to the following versions of Splunk® App for Lookup File Editing: 3.6.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters