Splunk® App for Lookup File Editing

User Guide

This documentation does not apply to the most recent version of Splunk® App for Lookup File Editing. For documentation on the most recent version, go to the latest release.

What's new in the Splunk App for Lookup File Editing

Here's what's new in each version of the Splunk App for Lookup File Editing.

Version 4.0.0

The following table lists the new features included in this release of the Splunk App for Lookup File Editing:

New feature Description
Toggle switch to turn on or turn off a KV store lookup on the Lookups page Turn on or turn off a KV store lookup. You can also see the total number of backups for each lookup, the total backup size for each lookup, and the current size of each lookup. See Review your saved lookup files and Create a new lookup in the Splunk App for Lookup File Editing.
Overview dashboard in the Health tab Manage your lookup files using metrics and visualizations on lookup file size, backups, and more. For example, you can track CSV lookups using a table visualization sorted by total backup size. See Review lookup file metrics and logs with dashboards.
Severity filter for the Logs dashboard in the Health tab Select a severity type for your logs to filter the Logs dashboard. Dashboard panels include Logs by Severity (over time), Log Severity, and Latest Log. You can also select results within these panels to open a new search. See Review lookup file metrics and logs with dashboards.
Backups and modifiable backup size limit for CSV lookups Save a backup for your CSV lookup. To prevent backups from filling up disk storage, you can edit the total backup size limit for a CSV lookup while creating a new CSV lookup or editing an existing one. See Edit the backup size limit for CSV lookups.
Upgraded dashboards Create and modify dashboards from the Search tab using the Splunk App for Lookup File Editing dashboards built with the Splunk Dashboard framework.

Version 3.6.0

This is the first Splunk supported release of the Splunk App for Lookup File Editing.

The Splunk App for Lookup File Editing is now part of the Splunk security portfolio and fully supported with an active Splunk Cloud or Splunk Enterprise license. No matter how you choose to deploy Splunk, you can edit, import, and export both KV store and CSV file lookups in an interface similar to Microsoft Excel with the Splunk App for Lookup File Editing.

Last modified on 02 June, 2023
Troubleshoot the Splunk App for Lookup File Editing   Known issues

This documentation applies to the following versions of Splunk® App for Lookup File Editing: 4.0.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters