1. Packages
  2. Splunk Provider
  3. API Docs
  4. LookupDefinition
Splunk v1.2.17 published on Wednesday, Apr 9, 2025 by Pulumi

splunk.LookupDefinition

Explore with Pulumi AI

Resource: splunk.LookupDefinition

Manage lookup definitions in Splunk. For more information on lookup definitions, refer to the official Splunk documentation: https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Aboutlookupsandfieldactions

Example Usage

import * as pulumi from "@pulumi/pulumi";
import * as splunk from "@pulumi/splunk";

const example = new splunk.LookupDefinition("example", {
    name: "example_lookup_definition",
    filename: "example_lookup_file.csv",
    acl: {
        owner: "admin",
        app: "search",
        sharing: "app",
        reads: ["*"],
        writes: ["admin"],
    },
});
Copy
import pulumi
import pulumi_splunk as splunk

example = splunk.LookupDefinition("example",
    name="example_lookup_definition",
    filename="example_lookup_file.csv",
    acl={
        "owner": "admin",
        "app": "search",
        "sharing": "app",
        "reads": ["*"],
        "writes": ["admin"],
    })
Copy
package main

import (
	"github.com/pulumi/pulumi-splunk/sdk/go/splunk"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)

func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		_, err := splunk.NewLookupDefinition(ctx, "example", &splunk.LookupDefinitionArgs{
			Name:     pulumi.String("example_lookup_definition"),
			Filename: pulumi.String("example_lookup_file.csv"),
			Acl: &splunk.LookupDefinitionAclArgs{
				Owner:   pulumi.String("admin"),
				App:     pulumi.String("search"),
				Sharing: pulumi.String("app"),
				Reads: pulumi.StringArray{
					pulumi.String("*"),
				},
				Writes: pulumi.StringArray{
					pulumi.String("admin"),
				},
			},
		})
		if err != nil {
			return err
		}
		return nil
	})
}
Copy
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Splunk = Pulumi.Splunk;

return await Deployment.RunAsync(() => 
{
    var example = new Splunk.LookupDefinition("example", new()
    {
        Name = "example_lookup_definition",
        Filename = "example_lookup_file.csv",
        Acl = new Splunk.Inputs.LookupDefinitionAclArgs
        {
            Owner = "admin",
            App = "search",
            Sharing = "app",
            Reads = new[]
            {
                "*",
            },
            Writes = new[]
            {
                "admin",
            },
        },
    });

});
Copy
package generated_program;

import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.splunk.LookupDefinition;
import com.pulumi.splunk.LookupDefinitionArgs;
import com.pulumi.splunk.inputs.LookupDefinitionAclArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;

public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }

    public static void stack(Context ctx) {
        var example = new LookupDefinition("example", LookupDefinitionArgs.builder()
            .name("example_lookup_definition")
            .filename("example_lookup_file.csv")
            .acl(LookupDefinitionAclArgs.builder()
                .owner("admin")
                .app("search")
                .sharing("app")
                .reads("*")
                .writes("admin")
                .build())
            .build());

    }
}
Copy
resources:
  example:
    type: splunk:LookupDefinition
    properties:
      name: example_lookup_definition
      filename: example_lookup_file.csv
      acl:
        owner: admin
        app: search
        sharing: app
        reads:
          - '*'
        writes:
          - admin
Copy

Validation Rules

When acl.sharing is set to user, the acl.read and acl.write fields must not be explicitly set. Setting them will trigger a validation error.

Create LookupDefinition Resource

Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

Constructor syntax

new LookupDefinition(name: string, args: LookupDefinitionArgs, opts?: CustomResourceOptions);
@overload
def LookupDefinition(resource_name: str,
                     args: LookupDefinitionArgs,
                     opts: Optional[ResourceOptions] = None)

@overload
def LookupDefinition(resource_name: str,
                     opts: Optional[ResourceOptions] = None,
                     filename: Optional[str] = None,
                     name: Optional[str] = None,
                     acl: Optional[LookupDefinitionAclArgs] = None)
func NewLookupDefinition(ctx *Context, name string, args LookupDefinitionArgs, opts ...ResourceOption) (*LookupDefinition, error)
public LookupDefinition(string name, LookupDefinitionArgs args, CustomResourceOptions? opts = null)
public LookupDefinition(String name, LookupDefinitionArgs args)
public LookupDefinition(String name, LookupDefinitionArgs args, CustomResourceOptions options)
type: splunk:LookupDefinition
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.

Parameters

name This property is required. string
The unique name of the resource.
args This property is required. LookupDefinitionArgs
The arguments to resource properties.
opts CustomResourceOptions
Bag of options to control resource's behavior.
resource_name This property is required. str
The unique name of the resource.
args This property is required. LookupDefinitionArgs
The arguments to resource properties.
opts ResourceOptions
Bag of options to control resource's behavior.
ctx Context
Context object for the current deployment.
name This property is required. string
The unique name of the resource.
args This property is required. LookupDefinitionArgs
The arguments to resource properties.
opts ResourceOption
Bag of options to control resource's behavior.
name This property is required. string
The unique name of the resource.
args This property is required. LookupDefinitionArgs
The arguments to resource properties.
opts CustomResourceOptions
Bag of options to control resource's behavior.
name This property is required. String
The unique name of the resource.
args This property is required. LookupDefinitionArgs
The arguments to resource properties.
options CustomResourceOptions
Bag of options to control resource's behavior.

Constructor example

The following reference example uses placeholder values for all input properties.

var lookupDefinitionResource = new Splunk.LookupDefinition("lookupDefinitionResource", new()
{
    Filename = "string",
    Name = "string",
    Acl = new Splunk.Inputs.LookupDefinitionAclArgs
    {
        App = "string",
        CanChangePerms = false,
        CanShareApp = false,
        CanShareGlobal = false,
        CanShareUser = false,
        CanWrite = false,
        Owner = "string",
        Reads = new[]
        {
            "string",
        },
        Removable = false,
        Sharing = "string",
        Writes = new[]
        {
            "string",
        },
    },
});
Copy
example, err := splunk.NewLookupDefinition(ctx, "lookupDefinitionResource", &splunk.LookupDefinitionArgs{
	Filename: pulumi.String("string"),
	Name:     pulumi.String("string"),
	Acl: &splunk.LookupDefinitionAclArgs{
		App:            pulumi.String("string"),
		CanChangePerms: pulumi.Bool(false),
		CanShareApp:    pulumi.Bool(false),
		CanShareGlobal: pulumi.Bool(false),
		CanShareUser:   pulumi.Bool(false),
		CanWrite:       pulumi.Bool(false),
		Owner:          pulumi.String("string"),
		Reads: pulumi.StringArray{
			pulumi.String("string"),
		},
		Removable: pulumi.Bool(false),
		Sharing:   pulumi.String("string"),
		Writes: pulumi.StringArray{
			pulumi.String("string"),
		},
	},
})
Copy
var lookupDefinitionResource = new LookupDefinition("lookupDefinitionResource", LookupDefinitionArgs.builder()
    .filename("string")
    .name("string")
    .acl(LookupDefinitionAclArgs.builder()
        .app("string")
        .canChangePerms(false)
        .canShareApp(false)
        .canShareGlobal(false)
        .canShareUser(false)
        .canWrite(false)
        .owner("string")
        .reads("string")
        .removable(false)
        .sharing("string")
        .writes("string")
        .build())
    .build());
Copy
lookup_definition_resource = splunk.LookupDefinition("lookupDefinitionResource",
    filename="string",
    name="string",
    acl={
        "app": "string",
        "can_change_perms": False,
        "can_share_app": False,
        "can_share_global": False,
        "can_share_user": False,
        "can_write": False,
        "owner": "string",
        "reads": ["string"],
        "removable": False,
        "sharing": "string",
        "writes": ["string"],
    })
Copy
const lookupDefinitionResource = new splunk.LookupDefinition("lookupDefinitionResource", {
    filename: "string",
    name: "string",
    acl: {
        app: "string",
        canChangePerms: false,
        canShareApp: false,
        canShareGlobal: false,
        canShareUser: false,
        canWrite: false,
        owner: "string",
        reads: ["string"],
        removable: false,
        sharing: "string",
        writes: ["string"],
    },
});
Copy
type: splunk:LookupDefinition
properties:
    acl:
        app: string
        canChangePerms: false
        canShareApp: false
        canShareGlobal: false
        canShareUser: false
        canWrite: false
        owner: string
        reads:
            - string
        removable: false
        sharing: string
        writes:
            - string
    filename: string
    name: string
Copy

LookupDefinition Resource Properties

To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

Inputs

In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

The LookupDefinition resource accepts the following input properties:

Filename This property is required. string
The filename for the lookup table, usually ending in .csv.
Name
This property is required.
Changes to this property will trigger replacement.
string
A unique name for the lookup definition within the app context.
Acl LookupDefinitionAcl
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
Filename This property is required. string
The filename for the lookup table, usually ending in .csv.
Name
This property is required.
Changes to this property will trigger replacement.
string
A unique name for the lookup definition within the app context.
Acl LookupDefinitionAclArgs
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
filename This property is required. String
The filename for the lookup table, usually ending in .csv.
name
This property is required.
Changes to this property will trigger replacement.
String
A unique name for the lookup definition within the app context.
acl LookupDefinitionAcl
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
filename This property is required. string
The filename for the lookup table, usually ending in .csv.
name
This property is required.
Changes to this property will trigger replacement.
string
A unique name for the lookup definition within the app context.
acl LookupDefinitionAcl
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
filename This property is required. str
The filename for the lookup table, usually ending in .csv.
name
This property is required.
Changes to this property will trigger replacement.
str
A unique name for the lookup definition within the app context.
acl LookupDefinitionAclArgs
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
filename This property is required. String
The filename for the lookup table, usually ending in .csv.
name
This property is required.
Changes to this property will trigger replacement.
String
A unique name for the lookup definition within the app context.
acl Property Map
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.

Outputs

All input properties are implicitly available as output properties. Additionally, the LookupDefinition resource produces the following output properties:

Id string
The provider-assigned unique ID for this managed resource.
Id string
The provider-assigned unique ID for this managed resource.
id String
The provider-assigned unique ID for this managed resource.
id string
The provider-assigned unique ID for this managed resource.
id str
The provider-assigned unique ID for this managed resource.
id String
The provider-assigned unique ID for this managed resource.

Look up Existing LookupDefinition Resource

Get an existing LookupDefinition resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

public static get(name: string, id: Input<ID>, state?: LookupDefinitionState, opts?: CustomResourceOptions): LookupDefinition
@staticmethod
def get(resource_name: str,
        id: str,
        opts: Optional[ResourceOptions] = None,
        acl: Optional[LookupDefinitionAclArgs] = None,
        filename: Optional[str] = None,
        name: Optional[str] = None) -> LookupDefinition
func GetLookupDefinition(ctx *Context, name string, id IDInput, state *LookupDefinitionState, opts ...ResourceOption) (*LookupDefinition, error)
public static LookupDefinition Get(string name, Input<string> id, LookupDefinitionState? state, CustomResourceOptions? opts = null)
public static LookupDefinition get(String name, Output<String> id, LookupDefinitionState state, CustomResourceOptions options)
resources:  _:    type: splunk:LookupDefinition    get:      id: ${id}
name This property is required.
The unique name of the resulting resource.
id This property is required.
The unique provider ID of the resource to lookup.
state
Any extra arguments used during the lookup.
opts
A bag of options that control this resource's behavior.
resource_name This property is required.
The unique name of the resulting resource.
id This property is required.
The unique provider ID of the resource to lookup.
name This property is required.
The unique name of the resulting resource.
id This property is required.
The unique provider ID of the resource to lookup.
state
Any extra arguments used during the lookup.
opts
A bag of options that control this resource's behavior.
name This property is required.
The unique name of the resulting resource.
id This property is required.
The unique provider ID of the resource to lookup.
state
Any extra arguments used during the lookup.
opts
A bag of options that control this resource's behavior.
name This property is required.
The unique name of the resulting resource.
id This property is required.
The unique provider ID of the resource to lookup.
state
Any extra arguments used during the lookup.
opts
A bag of options that control this resource's behavior.
The following state arguments are supported:
Acl LookupDefinitionAcl
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
Filename string
The filename for the lookup table, usually ending in .csv.
Name Changes to this property will trigger replacement. string
A unique name for the lookup definition within the app context.
Acl LookupDefinitionAclArgs
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
Filename string
The filename for the lookup table, usually ending in .csv.
Name Changes to this property will trigger replacement. string
A unique name for the lookup definition within the app context.
acl LookupDefinitionAcl
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
filename String
The filename for the lookup table, usually ending in .csv.
name Changes to this property will trigger replacement. String
A unique name for the lookup definition within the app context.
acl LookupDefinitionAcl
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
filename string
The filename for the lookup table, usually ending in .csv.
name Changes to this property will trigger replacement. string
A unique name for the lookup definition within the app context.
acl LookupDefinitionAclArgs
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
filename str
The filename for the lookup table, usually ending in .csv.
name Changes to this property will trigger replacement. str
A unique name for the lookup definition within the app context.
acl Property Map
Defines the access control list (ACL) for the lookup definition. See acl.md for more details.
filename String
The filename for the lookup table, usually ending in .csv.
name Changes to this property will trigger replacement. String
A unique name for the lookup definition within the app context.

Supporting Types

LookupDefinitionAcl
, LookupDefinitionAclArgs

App Changes to this property will trigger replacement. string
The app context for the resource. Required for updating saved search ACL properties. Allowed values are:The name of an app and system
CanChangePerms bool
Indicates if the active user can change permissions for this object. Defaults to true.
CanShareApp bool
Indicates if the active user can change sharing to app level. Defaults to true.
CanShareGlobal bool
Indicates if the active user can change sharing to system level. Defaults to true.
CanShareUser bool
Indicates if the active user can change sharing to user level. Defaults to true.
CanWrite bool
Indicates if the active user can edit this object. Defaults to true.
Owner string
User name of resource owner. Defaults to the resource creator. Required for updating any knowledge object ACL properties.nobody = All users may access the resource, but write access to the resource might be restricted.
Reads List<string>
Properties that indicate resource read permissions.
Removable bool
Indicates whether an admin or user with sufficient permissions can delete the entity.
Sharing Changes to this property will trigger replacement. string
Indicates how the resource is shared. Required for updating any knowledge object ACL properties.app: Shared within a specific appglobal: (Default) Shared globally to all apps.user: Private to a user
Writes List<string>
Properties that indicate resource write permissions.
App Changes to this property will trigger replacement. string
The app context for the resource. Required for updating saved search ACL properties. Allowed values are:The name of an app and system
CanChangePerms bool
Indicates if the active user can change permissions for this object. Defaults to true.
CanShareApp bool
Indicates if the active user can change sharing to app level. Defaults to true.
CanShareGlobal bool
Indicates if the active user can change sharing to system level. Defaults to true.
CanShareUser bool
Indicates if the active user can change sharing to user level. Defaults to true.
CanWrite bool
Indicates if the active user can edit this object. Defaults to true.
Owner string
User name of resource owner. Defaults to the resource creator. Required for updating any knowledge object ACL properties.nobody = All users may access the resource, but write access to the resource might be restricted.
Reads []string
Properties that indicate resource read permissions.
Removable bool
Indicates whether an admin or user with sufficient permissions can delete the entity.
Sharing Changes to this property will trigger replacement. string
Indicates how the resource is shared. Required for updating any knowledge object ACL properties.app: Shared within a specific appglobal: (Default) Shared globally to all apps.user: Private to a user
Writes []string
Properties that indicate resource write permissions.
app Changes to this property will trigger replacement. String
The app context for the resource. Required for updating saved search ACL properties. Allowed values are:The name of an app and system
canChangePerms Boolean
Indicates if the active user can change permissions for this object. Defaults to true.
canShareApp Boolean
Indicates if the active user can change sharing to app level. Defaults to true.
canShareGlobal Boolean
Indicates if the active user can change sharing to system level. Defaults to true.
canShareUser Boolean
Indicates if the active user can change sharing to user level. Defaults to true.
canWrite Boolean
Indicates if the active user can edit this object. Defaults to true.
owner String
User name of resource owner. Defaults to the resource creator. Required for updating any knowledge object ACL properties.nobody = All users may access the resource, but write access to the resource might be restricted.
reads List<String>
Properties that indicate resource read permissions.
removable Boolean
Indicates whether an admin or user with sufficient permissions can delete the entity.
sharing Changes to this property will trigger replacement. String
Indicates how the resource is shared. Required for updating any knowledge object ACL properties.app: Shared within a specific appglobal: (Default) Shared globally to all apps.user: Private to a user
writes List<String>
Properties that indicate resource write permissions.
app Changes to this property will trigger replacement. string
The app context for the resource. Required for updating saved search ACL properties. Allowed values are:The name of an app and system
canChangePerms boolean
Indicates if the active user can change permissions for this object. Defaults to true.
canShareApp boolean
Indicates if the active user can change sharing to app level. Defaults to true.
canShareGlobal boolean
Indicates if the active user can change sharing to system level. Defaults to true.
canShareUser boolean
Indicates if the active user can change sharing to user level. Defaults to true.
canWrite boolean
Indicates if the active user can edit this object. Defaults to true.
owner string
User name of resource owner. Defaults to the resource creator. Required for updating any knowledge object ACL properties.nobody = All users may access the resource, but write access to the resource might be restricted.
reads string[]
Properties that indicate resource read permissions.
removable boolean
Indicates whether an admin or user with sufficient permissions can delete the entity.
sharing Changes to this property will trigger replacement. string
Indicates how the resource is shared. Required for updating any knowledge object ACL properties.app: Shared within a specific appglobal: (Default) Shared globally to all apps.user: Private to a user
writes string[]
Properties that indicate resource write permissions.
app Changes to this property will trigger replacement. str
The app context for the resource. Required for updating saved search ACL properties. Allowed values are:The name of an app and system
can_change_perms bool
Indicates if the active user can change permissions for this object. Defaults to true.
can_share_app bool
Indicates if the active user can change sharing to app level. Defaults to true.
can_share_global bool
Indicates if the active user can change sharing to system level. Defaults to true.
can_share_user bool
Indicates if the active user can change sharing to user level. Defaults to true.
can_write bool
Indicates if the active user can edit this object. Defaults to true.
owner str
User name of resource owner. Defaults to the resource creator. Required for updating any knowledge object ACL properties.nobody = All users may access the resource, but write access to the resource might be restricted.
reads Sequence[str]
Properties that indicate resource read permissions.
removable bool
Indicates whether an admin or user with sufficient permissions can delete the entity.
sharing Changes to this property will trigger replacement. str
Indicates how the resource is shared. Required for updating any knowledge object ACL properties.app: Shared within a specific appglobal: (Default) Shared globally to all apps.user: Private to a user
writes Sequence[str]
Properties that indicate resource write permissions.
app Changes to this property will trigger replacement. String
The app context for the resource. Required for updating saved search ACL properties. Allowed values are:The name of an app and system
canChangePerms Boolean
Indicates if the active user can change permissions for this object. Defaults to true.
canShareApp Boolean
Indicates if the active user can change sharing to app level. Defaults to true.
canShareGlobal Boolean
Indicates if the active user can change sharing to system level. Defaults to true.
canShareUser Boolean
Indicates if the active user can change sharing to user level. Defaults to true.
canWrite Boolean
Indicates if the active user can edit this object. Defaults to true.
owner String
User name of resource owner. Defaults to the resource creator. Required for updating any knowledge object ACL properties.nobody = All users may access the resource, but write access to the resource might be restricted.
reads List<String>
Properties that indicate resource read permissions.
removable Boolean
Indicates whether an admin or user with sufficient permissions can delete the entity.
sharing Changes to this property will trigger replacement. String
Indicates how the resource is shared. Required for updating any knowledge object ACL properties.app: Shared within a specific appglobal: (Default) Shared globally to all apps.user: Private to a user
writes List<String>
Properties that indicate resource write permissions.

Package Details

Repository
Splunk pulumi/pulumi-splunk
License
Apache-2.0
Notes
This Pulumi package is based on the splunk Terraform Provider.