Skip to content

Lookups for the Splunk Add-on for NGINX

The Splunk Add-on for NGINX has the following lookups that map fields from NGINX systems to CIM-compliant values in the Splunk platform. The lookup files are located in $SPLUNK_HOME/etc/apps/Splunk_TA_nginx/lookups.

Filename Description
nginx_proxy_actions.csv Maps vendor_action to action, transport (when NGINX is configured as a proxy server)
nginx_httpstatus.csv Maps the action field to a status_description value for individual status code.