<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Cisco ASA: Why am I getting &amp;quot;The lookup table networkservice does not exist&amp;quot; in the alert messages? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127509#M10187</link>
    <description>&lt;P&gt;I had to disable  "SA-cisco-asa (3.0.1)" for these 'networkservice' errors to disappear.  Didn't disappear from rerunning a search.  But once I ran a new search on a new page after disabling the SA add-on.  All is well again.&lt;/P&gt;

&lt;P&gt;The only related parts I have are:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Splunk Add-on for Cisco ASA  Splunk_TA_cisco-asa 3.2.1&lt;/LI&gt;
&lt;LI&gt;Cisco ASA / PIX / FWSM Dashboards    SA-cisco-asa    3.0.1 &lt;STRONG&gt;Disabled and Soon to Be Removed&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Cisco ESA Email Security Appliance Dashboards    SA-cisco-esa    3.0.3&lt;/LI&gt;
&lt;LI&gt;Cisco Security Suite Splunk_CiscoSecuritySuite   3.1.0&lt;/LI&gt;
&lt;LI&gt;Splunk Add-on for Cisco ASA  Splunk_TA_cisco-asa 3.2.1&lt;/LI&gt;
&lt;LI&gt;Splunk Add-on for Cisco ESA  Splunk_TA_cisco-esa 1.1.0&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The firewall dashboards within the Cisco Security Suite all seem to be in working order still.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 19:21:09 GMT</pubDate>
    <dc:creator>sjh65</dc:creator>
    <dc:date>2020-09-28T19:21:09Z</dc:date>
    <item>
      <title>Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127498#M10176</link>
      <description>&lt;P&gt;Hi to everybody,&lt;/P&gt;

&lt;P&gt;I have a little problem. I can see in the alert messages, with this text:&lt;/P&gt;

&lt;P&gt;1) The lookup table 'networkservice' does not exist. It is referenced by configuration 'cisco:asa'.&lt;BR /&gt;
2) The lookup table 'networkservice' does not exist. It is referenced by configuration 'cisco:fwsm'.&lt;BR /&gt;
3) The lookup table 'networkservice' does not exist. It is referenced by configuration 'cisco:pix'.&lt;/P&gt;

&lt;P&gt;I have only Cisco ASA Firewall data.&lt;/P&gt;

&lt;P&gt;Any help, i'll be very grateful.&lt;/P&gt;

&lt;P&gt;Thanks a lot in advance&lt;/P&gt;

&lt;P&gt;Rubén&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 19:53:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127498#M10176</guid>
      <dc:creator>rubeniturrieta</dc:creator>
      <dc:date>2015-02-04T19:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127499#M10177</link>
      <description>&lt;P&gt;Hi @rubeniturrieta&lt;/P&gt;

&lt;P&gt;Are you referring to the Splunk Add-on for Cisco ASA in your post? &lt;A href="https://apps.splunk.com/app/1620/"&gt;https://apps.splunk.com/app/1620/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;or any other app/add-on?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 19:57:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127499#M10177</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-02-04T19:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127500#M10178</link>
      <description>&lt;P&gt;Yes, i'm refering to the Splunk Add-on for Cisco ASA&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 19:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127500#M10178</guid>
      <dc:creator>rubeniturrieta</dc:creator>
      <dc:date>2015-02-04T19:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127501#M10179</link>
      <description>&lt;P&gt;Thanks for clarifying. I just edited your post and tagged it with the official tag for the add-on. &lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 20:03:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127501#M10179</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-02-04T20:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127502#M10180</link>
      <description>&lt;P&gt;Ok, thanks you&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 20:04:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127502#M10180</guid>
      <dc:creator>rubeniturrieta</dc:creator>
      <dc:date>2015-02-04T20:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127503#M10181</link>
      <description>&lt;P&gt;Hi, there's no such lookup in the add-on... can you use btool to find out where the lookup is being referenced? &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Troubleshooting/Usebtooltotroubleshootconfigurations"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Troubleshooting/Usebtooltotroubleshootconfigurations&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2015 03:53:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127503#M10181</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-02-05T03:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127504#M10182</link>
      <description>&lt;P&gt;We are hit by the same problem: after upgrading the Cisco Security Suite from 3.0.3 to 3.1.0 these errors are displayed on any dashboard. Must be directly related to this version of the app...&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Stephan&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2015 08:44:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127504#M10182</guid>
      <dc:creator>swasserroth</dc:creator>
      <dc:date>2015-03-06T08:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127505#M10183</link>
      <description>&lt;P&gt;OK, probably I have found the root cause: as soon, as I disabled the application "Cisco ASA / PIX / FWSM Dashboards" (SA-cisco-asa), these errors vanished. The newest incarnation of the Cisco Security Suite seems to work without this older SA, maybe it should be de-installed. The embedded link of SA-cisco-asa pointing to the Splunk Apps website leads to a 404 error.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Stephan&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2015 16:19:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127505#M10183</guid>
      <dc:creator>swasserroth</dc:creator>
      <dc:date>2015-03-06T16:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127506#M10184</link>
      <description>&lt;P&gt;I have the same issue. The "networkservice" lookup definition is in the Cisco Security Suite App.  You can find it when clicking &amp;gt; Settings &amp;gt; Lookups &amp;gt; Lookup Definitions &amp;gt; pull down "App context" to all apps and do the search on the right hand side for "networkservice"&lt;/P&gt;

&lt;P&gt;I also have an issue where if I do a search in the Search and Reporting for anything involving my Cisco syslog and get the following: "The lookup table 'networkservice' does not exist. It is referenced by configuration 'cisco:asa'." so it's not just the Cisco Security Suite app affected.&lt;/P&gt;

&lt;P&gt;I disabled all the Splunk Cisco add-ons in the Cisco Security Suite app &amp;gt; Help &amp;gt; Setup &amp;gt; Check boxes for all the dashboards. and the SA-cisco-asa and still get errors on the Suite dashboard.&lt;/P&gt;

&lt;P&gt;If I go straight to a search: "eventtype=cisco-security-events" events populate.....&lt;/P&gt;

&lt;P&gt;If I do this search: "eventtype=cisco-security-events dest_ip!="255.255.255.255" dest_ip!="0.0.0.0" src_ip="*" " I get nothing... wierd&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127506#M10184</guid>
      <dc:creator>jimmy_ford</dc:creator>
      <dc:date>2020-09-28T19:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127507#M10185</link>
      <description>&lt;P&gt;In our case, the following Cisco-ASA-specific things were installed:&lt;BR /&gt;
 - SA-cisco-asa (3.0.1): this was causing the errors after upgrading the Splunk_CiscoSecuritySuit from 3.0.3 to 3.1.0 and therefore is now disabled&lt;BR /&gt;
 - Splunk_TA_cisco-asa (3.2.1)&lt;BR /&gt;
 - Splunk_CiscoSecuritySuite (3.2.1)&lt;/P&gt;

&lt;P&gt;With this configuration we do not get any errors regarding table "networkservice", because this table is defined inside the app Splunk_CiscoSecuritySuite (look at default/transforms.conf) and requires service-names-port-numbers.csv, which is located in the app-subdirectory lookups.&lt;/P&gt;

&lt;P&gt;IF you have installed SA-cisco-asa (3.0.1), you will find there in the props.conf more references to "networkservice", but the SA-cisco-asa does not define any transforms and does not contain the .csv-file needed -- thus the error.&lt;/P&gt;

&lt;P&gt;So far our analysis -- your mileage may vary &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Stephan&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127507#M10185</guid>
      <dc:creator>swasserroth</dc:creator>
      <dc:date>2020-09-28T19:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127508#M10186</link>
      <description>&lt;P&gt;Okay I deleted the SA cisco addon but the Cisco security app still doesn't work (the dashboard still shows blank)...&lt;/P&gt;

&lt;P&gt;And I still get: Eventtype 'cisco_esa* does not exist or is disabled' I only have asa enabled on the dashboard and the TA on the indexer.&lt;/P&gt;

&lt;P&gt;If I go straight to a search: "eventtype=cisco-security-events" events populate.....&lt;/P&gt;

&lt;P&gt;If I do this search: "eventtype=cisco-security-events dest_ip!="255.255.255.255" dest_ip!="0.0.0.0" src_ip="*" " I get nothing... weird&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:05:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127508#M10186</guid>
      <dc:creator>jimmy_ford</dc:creator>
      <dc:date>2020-09-28T19:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127509#M10187</link>
      <description>&lt;P&gt;I had to disable  "SA-cisco-asa (3.0.1)" for these 'networkservice' errors to disappear.  Didn't disappear from rerunning a search.  But once I ran a new search on a new page after disabling the SA add-on.  All is well again.&lt;/P&gt;

&lt;P&gt;The only related parts I have are:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Splunk Add-on for Cisco ASA  Splunk_TA_cisco-asa 3.2.1&lt;/LI&gt;
&lt;LI&gt;Cisco ASA / PIX / FWSM Dashboards    SA-cisco-asa    3.0.1 &lt;STRONG&gt;Disabled and Soon to Be Removed&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Cisco ESA Email Security Appliance Dashboards    SA-cisco-esa    3.0.3&lt;/LI&gt;
&lt;LI&gt;Cisco Security Suite Splunk_CiscoSecuritySuite   3.1.0&lt;/LI&gt;
&lt;LI&gt;Splunk Add-on for Cisco ASA  Splunk_TA_cisco-asa 3.2.1&lt;/LI&gt;
&lt;LI&gt;Splunk Add-on for Cisco ESA  Splunk_TA_cisco-esa 1.1.0&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The firewall dashboards within the Cisco Security Suite all seem to be in working order still.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:21:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127509#M10187</guid>
      <dc:creator>sjh65</dc:creator>
      <dc:date>2020-09-28T19:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127510#M10188</link>
      <description>&lt;P&gt;If you don't want to remove SA-cisco-asa, you may want to do a modification in 'SA-cisco-asa/default/transforms.conf' ;&lt;BR /&gt;
 1. create directory 'local' under 'SA-cisco-asa'&lt;BR /&gt;
 2. copy 'default/transforms.conf' to 'local/transforms.conf'&lt;BR /&gt;
 3. add following to 'local/transforms.conf';&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [networkservice]
filename = service-names-port-numbers.csv
max_matches = 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;OL&gt;
&lt;LI&gt;copy file 'Splunk_CiscoSecuritySuite/lookups/service-names-port-numbers.csv' to 'SA-cisco-asa/lookups/service-names-port-numbers.csv' &lt;/LI&gt;
&lt;LI&gt;restart splunk&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;no errors so far...&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 12:29:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127510#M10188</guid>
      <dc:creator>trymo</dc:creator>
      <dc:date>2015-04-21T12:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127511#M10189</link>
      <description>&lt;P&gt;I tried this and it works. The error: 'The lookup table 'networkservice' does not exist.' cleared up. I am wondering why when ever there are upgrades to applications we inevitably have to go through and find out what's missing. Thank you trymo for providing this answer.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 18:34:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127511#M10189</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2015-05-13T18:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Cisco ASA: Why am I getting "The lookup table networkservice does not exist" in the alert messages?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127512#M10190</link>
      <description>&lt;P&gt;I tried this workaround as well. It works like a charm.&lt;/P&gt;

&lt;P&gt;Thanks trymo for providing this answer.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2015 05:27:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Cisco-ASA-Why-am-I-getting-quot-The-lookup/m-p/127512#M10190</guid>
      <dc:creator>lindbergh_calde</dc:creator>
      <dc:date>2015-08-07T05:27:44Z</dc:date>
    </item>
  </channel>
</rss>

