Where are lookups stored in Splunk?
For example: $SPLUNK_HOME/etc/users/<username>/<app_name>/lookups/. Click Choose File to look for the CSV file to upload. The Splunk software saves your CSV file in $SPLUNK_HOME/etc/system/lookups/ , or in $SPLUNK_HOME/etc/<app_name>/lookups/ if the lookup belongs to a specific app...