<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error 'Could not find all of the specified lookup fields in the lookup table.' in Security</title>
    <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272518#M14975</link>
    <description>&lt;P&gt;Thank you.&lt;/P&gt;

&lt;P&gt;yeah i converted into CSV.&lt;/P&gt;

&lt;P&gt;I was just trying to work on the search command, i'm guessing that's what i got wrong. &lt;BR /&gt;
So i would have something like this:&lt;/P&gt;

&lt;P&gt;sourcetype=access_* | stats count by host | lookup Domain as referer_domain&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 10:19:37 GMT</pubDate>
    <dc:creator>papemalik</dc:creator>
    <dc:date>2020-09-29T10:19:37Z</dc:date>
    <item>
      <title>Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272514#M14971</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
i have this issue:&lt;BR /&gt;
Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'access_combined_wcookie' and lookup table 'malwaredomainlist'.&lt;BR /&gt;
Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'source::access.log.10|host::127.0.0.1|access_combined_wcookie' and lookup table 'malwaredomainlist'.&lt;/P&gt;

&lt;P&gt;I'm comparing access logs and a list of malware domain.&lt;BR /&gt;
 - I have tried putting a dummy column in 1st position, but no luck&lt;BR /&gt;
 - I have check the encoding of the excel file and changed it to US ASCII, but no luck, even UTF-8, still the same results&lt;BR /&gt;
 - In the search field my command is: index=* sourcetype=access_combined_wcookie&lt;/P&gt;

&lt;P&gt;I really need help on this one.&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:19:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272514#M14971</guid>
      <dc:creator>papemalik</dc:creator>
      <dc:date>2020-09-29T10:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272515#M14972</link>
      <description>&lt;P&gt;Can you share your search?  Sanitize what you need to for security.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 16:39:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272515#M14972</guid>
      <dc:creator>sjaworski</dc:creator>
      <dc:date>2016-07-18T16:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272516#M14973</link>
      <description>&lt;P&gt;Share what exactly?&lt;BR /&gt;
I need to be able to detect people that are trying to connect to suspicious domain.&lt;BR /&gt;
The plan is to be able to detect suspicious activity in a company. the malwaredomainlist is just one part of the search&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 08:59:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272516#M14973</guid>
      <dc:creator>papemalik</dc:creator>
      <dc:date>2016-07-19T08:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272517#M14974</link>
      <description>&lt;P&gt;Splunk is able to import any text-based formats, but Excel files with extensions like .xls og .xlsx are not text-based. This means that you cant read the Excel files directly in Splunk, but you have to convert it to CSV.  (I might be incorrect here, but I cant find any information about Splunk starting to support Excel files.)&lt;/P&gt;

&lt;P&gt;In addition you would have to extend your search string to include som kind of &lt;CODE&gt;lookup&lt;/CODE&gt;-query.&lt;/P&gt;

&lt;P&gt;There was a "guide" for something similar in the Splunk blog a few years back. It might help you out.&lt;BR /&gt;
&lt;A href="http://blogs.splunk.com/2015/01/30/working-with-spreadsheets-in-splunk-excel-csv-files/"&gt;http://blogs.splunk.com/2015/01/30/working-with-spreadsheets-in-splunk-excel-csv-files/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 09:53:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272517#M14974</guid>
      <dc:creator>tormodbp</dc:creator>
      <dc:date>2016-07-19T09:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272518#M14975</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;

&lt;P&gt;yeah i converted into CSV.&lt;/P&gt;

&lt;P&gt;I was just trying to work on the search command, i'm guessing that's what i got wrong. &lt;BR /&gt;
So i would have something like this:&lt;/P&gt;

&lt;P&gt;sourcetype=access_* | stats count by host | lookup Domain as referer_domain&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:19:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272518#M14975</guid>
      <dc:creator>papemalik</dc:creator>
      <dc:date>2020-09-29T10:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272519#M14976</link>
      <description>&lt;P&gt;The documentation for lookup can be found here:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/SearchReference/Lookup"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/SearchReference/Lookup&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;A quick extract of the syntax you need looks like this:&lt;BR /&gt;
    ... | lookup &lt;LOOKUP-TABLE-NAME&gt; (&lt;LOOKUP-FIELD&gt; [AS &lt;EVENT-FIELD&gt;]) [OUTPUT | OUTPUTNEW (&lt;LOOKUP-DESTFIELD&gt; [AS &lt;EVENT-DESTFIELD&gt;])&lt;/EVENT-DESTFIELD&gt;&lt;/LOOKUP-DESTFIELD&gt;&lt;/EVENT-FIELD&gt;&lt;/LOOKUP-FIELD&gt;&lt;/LOOKUP-TABLE-NAME&gt;&lt;/P&gt;

&lt;P&gt;For more information on CSV and external lookups, see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Knowledge/Addfieldsfromexternaldatasources"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/Knowledge/Addfieldsfromexternaldatasources&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 10:58:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272519#M14976</guid>
      <dc:creator>tormodbp</dc:creator>
      <dc:date>2016-07-19T10:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272520#M14977</link>
      <description>&lt;P&gt;I follow the tutorial with the http_status.csv&lt;/P&gt;

&lt;P&gt;I created the file, respected the encoding, did the the 3 steps in lookup parameters&lt;/P&gt;

&lt;P&gt;my command search:&lt;BR /&gt;
 sourcetype=access_* | lookup http_status status as status OUTPUTNEW status_description as description&lt;/P&gt;

&lt;P&gt;results:&lt;BR /&gt;
Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.&lt;/P&gt;

&lt;P&gt;Don't know what am i missing!!!!!&lt;/P&gt;

&lt;P&gt;I don't understand these two: [local=] [update=], can you enlighten these for me please?&lt;/P&gt;

&lt;P&gt;Thank you very much for taking the time to help, i really appreciate it, &lt;/P&gt;

&lt;P&gt;We will get through it (eventually) lol&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:19:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272520#M14977</guid>
      <dc:creator>papemalik</dc:creator>
      <dc:date>2020-09-29T10:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272521#M14978</link>
      <description>&lt;P&gt;What fields do you have in the sourcetype?&lt;/P&gt;

&lt;P&gt;The two parameters &lt;CODE&gt;local&lt;/CODE&gt;and &lt;CODE&gt;update&lt;/CODE&gt;are optional. You do not need them for the CSV http_status tutorial.&lt;/P&gt;

&lt;P&gt;[local=] specifies if you wan to run the lookup on the search head in stead of where you specified that the file is located.&lt;BR /&gt;
[update=] is used if the CSV is updated continuously or in real time, thus requiring a real-time search to include all changes that occur while the search is running. Update would then make Splunk account for the updates and automatically reflect the updates.&lt;/P&gt;

&lt;P&gt;You could try to make sure you can access the file by using &lt;CODE&gt;inputlookup&lt;/CODE&gt;. If this is successful then you know that you are able to read from the lookup.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup http_status 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 19 Jul 2016 11:27:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272521#M14978</guid>
      <dc:creator>tormodbp</dc:creator>
      <dc:date>2016-07-19T11:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272522#M14979</link>
      <description>&lt;P&gt;It's an access log, i have fields such as IP, status, domain, referer_domain (basically the same as Domain), domain country, bytes etc.&lt;/P&gt;

&lt;P&gt;Ok thank you for the explanation, i understand now.&lt;/P&gt;

&lt;P&gt;yes, Inputlookup is successful&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 13:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272522#M14979</guid>
      <dc:creator>papemalik</dc:creator>
      <dc:date>2016-07-19T13:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272523#M14980</link>
      <description>&lt;P&gt;I don't know if it matters, but i generally write &lt;CODE&gt;AS&lt;/CODE&gt; in capital.&lt;/P&gt;

&lt;P&gt;You could also try to specify the fields for the CSV-file in the transforms.conf using the syntax&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[http_status]
....
fields_list = &amp;lt;field1&amp;gt;, &amp;lt;field2&amp;gt; ..
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;other than that I'm not really sure. Can't really find anything wrong with the search command. If you followed the tutorial completely this should work.&lt;/P&gt;

&lt;P&gt;Sorry for not being able to help you&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 13:52:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272523#M14980</guid>
      <dc:creator>tormodbp</dc:creator>
      <dc:date>2016-07-19T13:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Error 'Could not find all of the specified lookup fields in the lookup table.'</title>
      <link>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272524#M14981</link>
      <description>&lt;P&gt;No AS didn't change much.&lt;/P&gt;

&lt;P&gt;specify the fields in the command search.&lt;/P&gt;

&lt;P&gt;Oh no, it's ok. i really appreciated the effort&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 14:07:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Error-Could-not-find-all-of-the-specified-lookup-fields-in-the/m-p/272524#M14981</guid>
      <dc:creator>papemalik</dc:creator>
      <dc:date>2016-07-19T14:07:44Z</dc:date>
    </item>
  </channel>
</rss>

