Follow the given steps to manually add the lookup to Splunk:
- Upload your productdescriptions.csv file to $SPLUNK_HOME/etc/apps/operational_intelligence/lookups directory (create the lookups directory if required)
- Add the following stanza to $SPLUNK_HOME/etc/apps operational_intelligence/local/transforms.conf (create the local directory if required):
[Product_Descriptions] filename = productdescriptions.csv
- Add the following stanza to $SPLUNK_HOME/etc/apps operational_intelligence/local/props.conf (create the local directory if required):
[log4j] LOOKUP-Product_Descriptions = Product_Descriptions itemId AS itemId OUTPUTNEW itemDescription AS ProductDescription, itemName AS ProductName