Example lookup using a Database

Thanks For Downloading!

Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:

Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into %PROGRAMFILES%\Splunk\etc\apps. Then restart Splunk using the splunk restart command or the GUI.

Unix/Linux: Decompress the downloaded file using a tool like tar -xvf and place the resulting folder into $SPLUNK_HOME\etc\apps. Then restart Splunk using the splunk restart command or the GUI.

Description

This is example of using the Splunk lookup search command to correlate a field that is in within Splunk with external field(s) that are in a database. The example is in the bin directory and is called countrylookup.py. After gunzip and tar extracting (tar zxvf dblookup.spl) the distribution, read the README.txt for instructions on usage.

The purpose of this example to show how Splunk can be used to correlate events with fields that reside in an external database.

.

Versions and Release Notes

Version 1.0.1 (current version - updated Oct 15, 2009)

Other Versions show »

Version 1.0 (updated Sep 2, 2009)

By downloading from Splunkbase, you agree to our Downloading Terms and Conditions »

Most of the applications and content on Splunkbase are submitted by parties other than us. That third-party content is the sole responsibility of the originator of that content. We are not responsible for any third-party content, whether or not we reviewed or moderated such content. You agree that you bear all risks ass ociated with using or relying on applications and content on Splunkbase. We do not in any way warrant the accuracy, reliability, completeness, usefulness, non-infringement, or quality of any applications or content on Splunkbase, regardless of who originated that content (including our employees, partners, affiliates or moderators), and even if an application is designated as "certified". We hereby disclaim all warranties, including but not limited to any implied warranties of merchantability or fitness for a particular purpose, relating to such applications or content. We shall not be liable or responsible in any way for any losses or damage of any kind, including lost profits or other indirect or consequential damages, relating to your use of or reliance upon any applications or content on Splunkbase.

About This App

Version 1.0.1
Last Updated: Oct 15, 2009
Author: ndoshi
Splunk Version: 4.x
Price: Free
License: Creative Commons
Rating:
  (0 votes)
Please login to rate this app.
Ask a Question

Related Questions:

Preview App: