Use the Splunk App for Lookup File Editing to import and edit KV store or CSV lookups within the Splunk platform. This app provides an Excel-like interface for importing, editing, and exporting lookup files.
The app interface is comprised of a series of tabs that offer different functions:
- New Lookup
Use the Lookups tab to view a list of your saved lookup files. Sort the view by any column header. Filter or search the list by share settings, lookup type, affiliated app, or by name.
Click the name of any listed lookup to view and edit that lookup. Depending on app permissions you can also export, open in search, and delete any lookup from the list view.
Use the New Lookup tab to create a new CSV or KV store lookup. For specific how-to steps, see, Create a new lookup in the Splunk App for Lookup File Editing.
Use the Health tab to view the latest log and debug information. The tab offers the options of Logs and Status:
- Use the Logs dashboard to select a time range and severity type for your logs. Dashboard panels include Logs by Severity (over time), Log Severity, and Latest Log. You can click results within these panels to open a new search.
- Use the Status tab dashboard for the current status of the Splunk App for Lookup File Editing.
The application does not work if one of the REST Handlers are offline.
Use the Search tab to perform a Splunk search, and explore you datasets, reports, alerts, and dashboards. These resources are not limited to the Splunk App for Lookup File Editing.
About the Splunk App for Lookup File Editing
Create a new lookup in the Splunk App for Lookup File Editing
This documentation applies to the following versions of Splunk® App for Lookup File Editing: 3.6.0