Splunk

Lookup tables (csv)
I don't know why it took me so long to get this. Documenting in the hopes that using my own words will help future!me.

Table file

 * 1) Go to Settings → Lookups.
 * 2) Click "Lookup table files", then "New".
 * 3) * Destination app: search
 * 4) * Destination filename: filename.csv
 * 5) Click Save.
 * 6) Edit the permissions.
 * 7) Change to "All apps", then click Save.

Lookup definition

 * 1) Go to Settings → Lookups.
 * 2) Click "Lookup definitions", then "New".
 * 3) * Destination app: search
 * 4) * Name: [whatever]
 * 5) * Type: file-based
 * 6) * Lookup file: filename.csv
 * 7) Click Save.
 * 8) Edit the permissions.
 * 9) Change to "All apps", then click Save.

Automatic lookup

 * 1) Go to Settings → Lookups.
 * 2) Click "Automatic lookups", then "New".
 * 3) * Destination app: search
 * 4) * Name: [whatever]
 * 5) * Lookup file: filename.csv
 * 6) * Apply to: [whichever]
 * 7) * named: [whatever]
 * 8) * Lookup input fields: [CSV lookup column] = [apply-to fieldname]
 * 9) * Lookup output fields: [CSV data column] = [new column name]
 * 10) Click Save.
 * 11) Edit the permissions.
 * 12) Change to "All apps", then click Save.