<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Has anyone encountered this error: Asset and Identity Management issue? in Security</title>
    <link>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/753875#M18524</link>
    <description>&lt;P&gt;Does anyone come across this error "&lt;SPAN class=""&gt;file=identity_manager.py:lookup_last_update:391&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN class=""&gt;status=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Lookup&lt;/SPAN&gt; &lt;SPAN class=""&gt;file&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;error&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;unknown&lt;/SPAN&gt; &lt;SPAN class=""&gt;path&lt;/SPAN&gt; &lt;SPAN class=""&gt;or&lt;/SPAN&gt; &lt;SPAN class=""&gt;update&lt;/SPAN&gt; &lt;SPAN class=""&gt;time&lt;/SPAN&gt;&lt;SPAN&gt;"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please help me.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Oct 2025 13:41:58 GMT</pubDate>
    <dc:creator>lalithasegu</dc:creator>
    <dc:date>2025-10-02T13:41:58Z</dc:date>
    <item>
      <title>Has anyone encountered this error: Asset and Identity Management issue?</title>
      <link>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/572895#M15685</link>
      <description>&lt;P&gt;Has anyone encountered this issue and how did you fixed it on Splunkcloud and Enterprise Security "Identity:&amp;nbsp;&lt;STRONG&gt;An error occurred while the Asset and Identity Management modular input ran" ?&amp;nbsp;&lt;/STRONG&gt; When I checked the error it is saying that&amp;nbsp;&lt;STRONG&gt;Lookup file error, unknown path or update time.&amp;nbsp;&lt;/STRONG&gt;Pretty sure lookups is existing but I am not sure what it means by update time?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Paaattt_1-1635463243381.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16655iCA73917776FDF61B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Paaattt_1-1635463243381.png" alt="Paaattt_1-1635463243381.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Paaattt_0-1635463222543.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16654i29CE1A3A479604B9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Paaattt_0-1635463222543.png" alt="Paaattt_0-1635463222543.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 14:09:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/572895#M15685</guid>
      <dc:creator>Paaattt</dc:creator>
      <dc:date>2022-09-21T14:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Asset and Identity Management issue</title>
      <link>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/613940#M16371</link>
      <description>&lt;P&gt;In the same boat as you, have you figured this out? By the way, I switched over to SA-CrowdStrike with CrowdStrike Device TA and use it to build an asset tables.&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234516"&gt;@Paaattt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 13:47:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/613940#M16371</guid>
      <dc:creator>rav_diesel</dc:creator>
      <dc:date>2022-09-21T13:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone encountered this error: Asset and Identity Management issue?</title>
      <link>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/642649#M16958</link>
      <description>&lt;P&gt;Any updates?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 12:12:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/642649#M16958</guid>
      <dc:creator>anel</dc:creator>
      <dc:date>2023-05-09T12:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone encountered this error: Asset and Identity Management issue?</title>
      <link>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/654019#M17204</link>
      <description>&lt;P&gt;Has anyone found the reason for this error message yet, and how to fix it?&lt;BR /&gt;&lt;BR /&gt;We're encountering the same error. Both the lookup file and the lookup definition surely exists, and both are available when using inputlookup in the search bar. Also we've checked that they are available in the Splunk ES app. The identity list in Splunk ES does populate with data, so the "identity lookup merging searches" are in fact working, meaning that surely the "lookup file path exists" and is available for Splunk ES.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 07:04:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/654019#M17204</guid>
      <dc:creator>hettervik</dc:creator>
      <dc:date>2023-08-11T07:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone encountered this error: Asset and Identity Management issue?</title>
      <link>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/656069#M17241</link>
      <description>&lt;P&gt;We've looked a bit more into this case. The error is coming from the script "identity_manager.py" in the app "SA-IdentityManagement". The error is generated in the following "for" loop.&lt;/P&gt;&lt;PRE&gt;for url, path, size, last_updated in update_times:&lt;BR /&gt;  if path and last_updated:&lt;BR /&gt;    lookup[url] = last_updated&lt;BR /&gt;  else:&lt;BR /&gt;    logger.error('status="Lookup file error, unknown path or update time" name=%s', url)&lt;/PRE&gt;&lt;P&gt;The "update_times" array comes from the method "get_lookup_table_file_update_times", which again comes ultimately from the Python package "&lt;A href="https://docs.python.org/3/library/importlib.html" target="_self"&gt;importlib.util.spec_from_file_location&lt;/A&gt;". We were thinking that this error might be from this package, and not from Splunk per se, but when we look at the actual lookup file CSV in the Linux OS, it is there and has the last modified time value sat, so that is not the cause either.&lt;BR /&gt;&lt;BR /&gt;So, still haven't figured this out.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 09:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/656069#M17241</guid>
      <dc:creator>hettervik</dc:creator>
      <dc:date>2023-08-30T09:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone encountered this error: Asset and Identity Management issue?</title>
      <link>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/665877#M17343</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This error exists since the KVstore is being used as opposed to a CSV file and does not interfere with the functionality of lookup creation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See the known issue at: &lt;A href="https://splunk-sa-crowdstrike.ztsplunker.com/releases/issues/" target="_blank"&gt;https://splunk-sa-crowdstrike.ztsplunker.com/releases/issues/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 16:01:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/665877#M17343</guid>
      <dc:creator>ZachTheSplunkr</dc:creator>
      <dc:date>2023-10-23T16:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone encountered this error: Asset and Identity Management issue?</title>
      <link>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/753875#M18524</link>
      <description>&lt;P&gt;Does anyone come across this error "&lt;SPAN class=""&gt;file=identity_manager.py:lookup_last_update:391&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN class=""&gt;status=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Lookup&lt;/SPAN&gt; &lt;SPAN class=""&gt;file&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;error&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;unknown&lt;/SPAN&gt; &lt;SPAN class=""&gt;path&lt;/SPAN&gt; &lt;SPAN class=""&gt;or&lt;/SPAN&gt; &lt;SPAN class=""&gt;update&lt;/SPAN&gt; &lt;SPAN class=""&gt;time&lt;/SPAN&gt;&lt;SPAN&gt;"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please help me.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 13:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/753875#M18524</guid>
      <dc:creator>lalithasegu</dc:creator>
      <dc:date>2025-10-02T13:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone encountered this error: Asset and Identity Management issue?</title>
      <link>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/753876#M18525</link>
      <description>&lt;P&gt;In case if you find solution for this. please share it with me. really helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 13:42:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Has-anyone-encountered-this-error-Asset-and-Identity-Management/m-p/753876#M18525</guid>
      <dc:creator>lalithasegu</dc:creator>
      <dc:date>2025-10-02T13:42:50Z</dc:date>
    </item>
  </channel>
</rss>

