Rather than creating the lookup locally inside Splunk, as we did with this recipe, Splunk DB Connect allows you to create a lookup table that uses an external database table as its source. This lookup can be cached, so that the database is not continually searched by Splunk users.
- From within the DB Connect application, select the Data Lab menu item and the Lookups tab. Click the New Lookup button.
- Run the following search to set the reference search for the lookup. After the search completes, click the Next button:
index=main sourcetype=log4j itemId=*
The following is the screenshot that appears after running the preceding search:
- Select the products_databaseConnection, productsdbCatalog, ...