home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Prerequisites for Existing App Users

Due to configuration storage and encryption changes in Splunk, if you are currently using the Lookout Splunk App 1.4.1 and below from Splunkbase, follow the steps below to migrate your configuration. This ensures you do not index duplicate events when updating to the new version of the app:

  1. Retrieve your Enterprise name and API Key strings from the key-value store:
    1. In the top navigation bar, click Datasets, then select kvstore_lookup.
    2. Copy the ent and application_key values exactly, including spacing and capitalization.
  2. Follow the installation steps below, and provide the Enterprise name and API Key as specified in Step 2C.

    Providing the exact Enterprise and API Key values ensures that the Splunk App picks up from the same streamPosition where it previously left off, so that you are not flooded with the full backlog of events since the creation of the tenant.