The part of a lookup configuration that defines the data type and connection parameters used when comparing event fields. Splunk Enterprise lookup definitions can connect to lookup tables in .csv files, .kmz files, external data sources, and KVStore collections.

