<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Networks for Splunk v 6.1.1: Receiving error &amp;quot;lookup table is empty or has not yet been replicated to in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/527786#M64071</link>
    <description>&lt;P&gt;Thanks to&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/32273"&gt;@fverdi&lt;/a&gt;&amp;nbsp;for the tip.&amp;nbsp; The error seems to be due to the empty automatic lookup.&amp;nbsp; &amp;nbsp;So I added a dummy entry into the minemeldfeeds kvstore collection to get rid of the warning message when searching the paloalto data in splunk.&lt;BR /&gt;&lt;BR /&gt;Here's the curl command to add the entry.&amp;nbsp; Just remember to remove the entry if you enable the minemeld feeds.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;curl -k -u admin https://&amp;lt;SEARCH-HEAD&amp;gt;:8089/servicesNS/nobody/Splunk_TA_paloalto/storage/collections/data/minemeldfeeds -H "Content-Type: application/json" -d '{ "myKey": "temp" , "description": "remove this entry from this collection when enabling minemeld feeds"}&lt;/P&gt;</description>
    <pubDate>Tue, 03 Nov 2020 17:12:40 GMT</pubDate>
    <dc:creator>manikumarv</dc:creator>
    <dc:date>2020-11-03T17:12:40Z</dc:date>
    <item>
      <title>Palo Alto Networks for Splunk v 6.1.1: Receiving error "lookup table is empty or has not yet been replicated to the search peer"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401328#M48946</link>
      <description>&lt;P&gt;This warning is present in the Job control drop-down on search heads:&lt;BR /&gt;
&lt;CODE&gt;The 'minemeldfeeds_lookup' KV Store lookup table is empty or has not yet been replicated to the search peer (path used is: /opt/splunk/var/run/searchpeers/...)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;The error is cited for 3 of the 5 indexers in a cluster, and the search heads are in a cluster.&lt;BR /&gt;
&lt;STRONG&gt;Is there a resolution appropriate for this version or a step we missed?&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Splunk v 7.2.5.1&lt;BR /&gt;
Palo Alto Networks Add-on for Splunk v 6.1.1&lt;BR /&gt;
Splunk Enterprise Security is in use, and there is no other Palo Alto "app" in place.  (From the installation guide: "The Add-on can be used with or without the App.")&lt;BR /&gt;
The add-on is in place on the search heads, indexers, and heavy forwarders.&lt;/P&gt;

&lt;P&gt;One of the previous answers mentioned setting replicate=true ...&lt;BR /&gt;
From what I can tell, that was already set by default in this version of the add-on due to these two excerpts:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Splunk_TA_paloalto/default/transforms.conf&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;PRE&gt;&lt;CODE&gt;[minemeldfeeds_lookup]
external_type = kvstore
collection = minemeldfeeds
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Splunk_TA_paloalto/default/collections.conf&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;PRE&gt;&lt;CODE&gt;[minemeldfeeds]
replicate = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Unlike other posts on answers.splunk, we did not have an upgrade involved.  That made most of the recommendations and previously accepted answers unhelpful.&lt;BR /&gt;&lt;BR /&gt;
The kvstore migrate command did not seem to apply to this scenario and version; nothing I found suggested there was a way to force the knowledge bundle from search head to indexers (if that is the issue)- similar to the sync command available for kvstore, and shcluster-replicated-config.  &lt;/P&gt;

&lt;P&gt;Any tips would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:46:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401328#M48946</guid>
      <dc:creator>jwightman2</dc:creator>
      <dc:date>2020-09-30T00:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks for Splunk v 6.1.1: Receiving error "lookup table is empty or has not yet been replicated to the search peer"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401329#M48947</link>
      <description>&lt;P&gt;Have you found a solution?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2019 16:59:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401329#M48947</guid>
      <dc:creator>eugenek</dc:creator>
      <dc:date>2019-09-11T16:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks for Splunk v 6.1.1: Receiving error "lookup table is empty or has not yet been replicated to the search peer"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401330#M48948</link>
      <description>&lt;P&gt;From 2019/09/11, originally accidentally posted as an answer:&lt;BR /&gt;
No solutions, good news, or follow-ups from any type of support personnel. (Modifications to post/formatting/title happened at the time of submission, possibly by evzhang_splunk.)&lt;/P&gt;

&lt;P&gt;After letting a search job complete for a test today, the error is shown for all 5 indexers in the cluster.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 18:59:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401330#M48948</guid>
      <dc:creator>jwightman2</dc:creator>
      <dc:date>2019-11-14T18:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks for Splunk v 6.1.1: Receiving error "lookup table is empty or has not yet been replicated to the search peer"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401331#M48949</link>
      <description>&lt;P&gt;It looks like the same problem was reported on Github (for PaloAltoNetworks/SplunkforPaloAltoNetworks) on 2019/10/24.  At the time of writing (2019/11/14), it &lt;STRONG&gt;also&lt;/STRONG&gt; has no response.&lt;BR /&gt;
&lt;A href="https://github.com/PaloAltoNetworks/SplunkforPaloAltoNetworks/issues/95"&gt;https://github.com/PaloAltoNetworks/SplunkforPaloAltoNetworks/issues/95&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 19:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401331#M48949</guid>
      <dc:creator>jwightman2</dc:creator>
      <dc:date>2019-11-14T19:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks for Splunk v 6.1.1: Receiving error "lookup table is empty or has not yet been replicated to the search peer"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401332#M48950</link>
      <description>&lt;P&gt;We're having the same error with 6.1.1 of the app and 7.3.3 of Splunk. I'd help if I could, but you're not alone.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 17:46:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401332#M48950</guid>
      <dc:creator>keith_d</dc:creator>
      <dc:date>2020-01-13T17:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks for Splunk v 6.1.1: Receiving error "lookup table is empty or has not yet been replicated to the search peer"</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401333#M48951</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I found this question while looking up a similar answer for my own custom KVStore. I don't have a solution for the Palo Alto addon directly, but I resolved my issues by adding &lt;CODE&gt;append=True key_field=_key&lt;/CODE&gt; to my kvstore outputlookup.&lt;/P&gt;

&lt;P&gt;What appears to be the issue in my case is that you need to specify &lt;CODE&gt;key_field=&amp;lt;field&amp;gt;&lt;/CODE&gt; if you are are manually evaling your &lt;CODE&gt;_key&lt;/CODE&gt; field and are outputting to an empty KVStore.&lt;/P&gt;

&lt;P&gt;I would check to see if the KVStore output search his manually setting the key and not including that field. I've found if you remove the manual eval or add the &lt;CODE&gt;key_field=&amp;lt;field&amp;gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;You haven't had any answers or suggestions pertaining to your exact issue, but I hope this can help.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 13:07:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/401333#M48951</guid>
      <dc:creator>jadamsplunk</dc:creator>
      <dc:date>2020-03-27T13:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks for Splunk v 6.1.1: Receiving error "lookup table is empty or has not ye</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/503637#M62091</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I recently came got annoyed of the problem and finally did some investigation.&lt;/P&gt;&lt;P&gt;Looks like the error is complaining about the kvstore of minemeldfeeds_lookup as being empty.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The original minemeldfeeds_lookup was trying to get results from sourcetype=pan:minemeld and we don't have a subscription for that.&lt;/P&gt;&lt;P&gt;Here's a workaround (referenced here @ &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Outputlookup" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Outputlookup&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;| makeresults | eval name="xyz" | eval token="12345"| outputlookup minemeldfeeds_lookup&lt;/P&gt;&lt;P&gt;This will add an entry and we won't have a blank file anymore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck and keep on splunking.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 21:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/503637#M62091</guid>
      <dc:creator>splunk-the-prob</dc:creator>
      <dc:date>2020-06-09T21:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Networks for Splunk v 6.1.1: Receiving error "lookup table is empty or has not yet been replicated to</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/527786#M64071</link>
      <description>&lt;P&gt;Thanks to&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/32273"&gt;@fverdi&lt;/a&gt;&amp;nbsp;for the tip.&amp;nbsp; The error seems to be due to the empty automatic lookup.&amp;nbsp; &amp;nbsp;So I added a dummy entry into the minemeldfeeds kvstore collection to get rid of the warning message when searching the paloalto data in splunk.&lt;BR /&gt;&lt;BR /&gt;Here's the curl command to add the entry.&amp;nbsp; Just remember to remove the entry if you enable the minemeld feeds.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;curl -k -u admin https://&amp;lt;SEARCH-HEAD&amp;gt;:8089/servicesNS/nobody/Splunk_TA_paloalto/storage/collections/data/minemeldfeeds -H "Content-Type: application/json" -d '{ "myKey": "temp" , "description": "remove this entry from this collection when enabling minemeld feeds"}&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 17:12:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Palo-Alto-Networks-for-Splunk-v-6-1-1-Receiving-error-quot/m-p/527786#M64071</guid>
      <dc:creator>manikumarv</dc:creator>
      <dc:date>2020-11-03T17:12:40Z</dc:date>
    </item>
  </channel>
</rss>

