Navigate and use the Splunk App for Lookup File Editing

Using the Splunk App for Lookup File Editing, you can edit, import, and export KV store and CSV file lookups in an interface similar to Microsoft Excel.

You can use the following tabs in the app interface:

  • Lookups
  • New Lookup
  • Health
  • Search

Lookups

Select the Lookups tab to view a list of your saved lookup files. Sort the view by any column header. Filter or search the list by share settings, lookup type, affiliated app, or by name.

This image shows the Lookups tab of the Splunk App for Lookup File Editing App.

Select the name of any listed lookup to view and edit that lookup. Depending on your app permissions, you can also export, open in search, and delete any lookup from the list view.

Health

Select the Health tab to view the latest log and debug information. The tab offers the options of Logs and Status:

  • Use the Logs dashboard to select a time range and severity type for your logs. Dashboard panels include Logs by Severity (over time), Log Severity, and Latest Log. You can select results within these panels to open a new search.
  • Use the Status tab dashboard for the current status of the Splunk App for Lookup File Editing.
Note: The application does not work if one of the REST Handlers is offline.

This image shows the Health tab of the Splunk App for Lookup File Editing App. There are two options within the tab drop-down menu, one for Logs and the other for Status. This image shows the Status page.

Search