<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Streamed search execute failed because: Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table. in Security</title>
    <link>https://community.splunk.com/t5/Security/Streamed-search-execute-failed-because-Error-in-lookup-command/m-p/406540#M15501</link>
    <description>&lt;P&gt;I have defined the below lookup in &lt;STRONG&gt;&lt;EM&gt;search app&lt;/EM&gt;&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;transforms.conf&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
[lookup_hosts]&lt;BR /&gt;
external_type = kvstore&lt;BR /&gt;
collection = hosts&lt;BR /&gt;
case_sensitive_match = 1&lt;BR /&gt;
fields_list = _key,hostname,env,dataCenter,appid,zone,hostname_fwrdr&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;collections.conf&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
[hosts]&lt;BR /&gt;
replicate = true&lt;BR /&gt;
accelerated_fields.hostname = { "hostname": 1 }&lt;BR /&gt;
field.env = string&lt;BR /&gt;
field.appid = string&lt;BR /&gt;
field.hostname = string&lt;BR /&gt;
field.dataCenter = string&lt;BR /&gt;
field.zone = string&lt;BR /&gt;
field.hostname_fwrdr = string&lt;/P&gt;

&lt;P&gt;I have defined below automatic lookup in &lt;STRONG&gt;&lt;EM&gt;props.conf&lt;/EM&gt;&lt;/STRONG&gt; against the corresponding sourcetype&lt;BR /&gt;
[st--acess]&lt;BR /&gt;
ANNOTATE_PUNCT = false&lt;BR /&gt;
LOOKUP-hosts = lookup_hosts hostname_fwrdr as host OUTPUTNEW env,dataCenter,hostname,zone&lt;/P&gt;

&lt;P&gt;Automatic lookup didn't work and when i tried Searching data from searchhead with below syntax:&lt;BR /&gt;
 sourcetype="st-access"| lookup lookup_hosts hostname_fwrdr as host outputnew env&lt;/P&gt;

&lt;P&gt;I got the error as below&lt;BR /&gt;
&lt;STRONG&gt;2 errors occurred while the search was executing. Therefore, search results might be incomplete. Hide errors.&lt;BR /&gt;
[idx01] Streamed search execute failed because: Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.&lt;BR /&gt;
[idx02] Streamed search execute failed because: Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Please suggest a way to make this working.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:47:01 GMT</pubDate>
    <dc:creator>potluri_88</dc:creator>
    <dc:date>2020-09-29T22:47:01Z</dc:date>
    <item>
      <title>Streamed search execute failed because: Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.</title>
      <link>https://community.splunk.com/t5/Security/Streamed-search-execute-failed-because-Error-in-lookup-command/m-p/406540#M15501</link>
      <description>&lt;P&gt;I have defined the below lookup in &lt;STRONG&gt;&lt;EM&gt;search app&lt;/EM&gt;&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;transforms.conf&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
[lookup_hosts]&lt;BR /&gt;
external_type = kvstore&lt;BR /&gt;
collection = hosts&lt;BR /&gt;
case_sensitive_match = 1&lt;BR /&gt;
fields_list = _key,hostname,env,dataCenter,appid,zone,hostname_fwrdr&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;collections.conf&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
[hosts]&lt;BR /&gt;
replicate = true&lt;BR /&gt;
accelerated_fields.hostname = { "hostname": 1 }&lt;BR /&gt;
field.env = string&lt;BR /&gt;
field.appid = string&lt;BR /&gt;
field.hostname = string&lt;BR /&gt;
field.dataCenter = string&lt;BR /&gt;
field.zone = string&lt;BR /&gt;
field.hostname_fwrdr = string&lt;/P&gt;

&lt;P&gt;I have defined below automatic lookup in &lt;STRONG&gt;&lt;EM&gt;props.conf&lt;/EM&gt;&lt;/STRONG&gt; against the corresponding sourcetype&lt;BR /&gt;
[st--acess]&lt;BR /&gt;
ANNOTATE_PUNCT = false&lt;BR /&gt;
LOOKUP-hosts = lookup_hosts hostname_fwrdr as host OUTPUTNEW env,dataCenter,hostname,zone&lt;/P&gt;

&lt;P&gt;Automatic lookup didn't work and when i tried Searching data from searchhead with below syntax:&lt;BR /&gt;
 sourcetype="st-access"| lookup lookup_hosts hostname_fwrdr as host outputnew env&lt;/P&gt;

&lt;P&gt;I got the error as below&lt;BR /&gt;
&lt;STRONG&gt;2 errors occurred while the search was executing. Therefore, search results might be incomplete. Hide errors.&lt;BR /&gt;
[idx01] Streamed search execute failed because: Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.&lt;BR /&gt;
[idx02] Streamed search execute failed because: Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Please suggest a way to make this working.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:47:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Streamed-search-execute-failed-because-Error-in-lookup-command/m-p/406540#M15501</guid>
      <dc:creator>potluri_88</dc:creator>
      <dc:date>2020-09-29T22:47:01Z</dc:date>
    </item>
  </channel>
</rss>

