product
- Why choose Splunk
- Installation record
- price
- Splunk Enterprise Security
- Splunk Phantom (SOAR)
- Splunk ITSI (Next Generation IT Operations)
- Splunk Observability Cloud
- Splunk UBA
- Macnica CSIRT App Basic
- App for Splunk for Financial Institutions
- Splunk Analytics for Hadoop
- About Apps
- Splunk Edge Hub
- What is Splunk
service
- Dashboard/SPL Creation Pack [Implementation/Building Support]
- Version upgrade service [implementation and construction support]
- Smart Security Monitoring App [Original App/Service]
- Splunk × LANSCOPE Original App [Original App/Service]
- Security Monitoring App for Box [Original App/Service]
- Cloud Security Monitoring App [Original App/Service]
- List of services
- Macnica Premium Support for Splunk (utilization support, version upgrade monitoring)
- Macnica Premium Support for Splunk Skill Up Package
Specifications/Technical Information
Application for evaluation machine
- FAQ
Timing of lookup table reference by alerts and reports
- release date
- 2016-05-27
- last updated
- 2024-07-01
- version
- Splunk Enterprise 9.0.4
- Overview
- This article describes how to reflect lookup table updates in real-time searches.
- Reference information
- content
-
Real-time search lookup table reference timing
When using a real-time search as an alert/report, the lookup table referenced will continue to be the one from the time the real-time search was first executed.
The update=true option is required to always reflect the latest lookup table in real-time search.
- Without update=true option
Real-time search refers only to the first lookup table, and subsequent updates to the lookup table are not reflected in real-time search.
Search execution example) sourcetype=cc | lookup testlookup zz OUTPUT xx yy
- If you have the update=true option
Real-time search always refers to the latest lookup table.
Search execution example) sourcetype=cc | lookup update=true testlookup zz OUTPUT xx yy
that's all
In charge of Macnica Splunk Co., Ltd.
- TEL:045-476-2010
- E-mail:splunk-sales@macnica.co.jp
Weekdays: 9:00-17:00