<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why can I not expand lookup field due to a reference cycle in the lookup configuration? in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/543455#M563</link>
    <description>&lt;P&gt;on Splunk Cloud (8.1.2101.1) I'm encountering a warning message in my search results - trying to figure out why this is popping up. Anybody have any idea what this message means and how to resolve it?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="splunkwarning.PNG" style="width: 685px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13279i69C213568EB60637/image-dimensions/685x77?v=v2" width="685" height="77" role="button" title="splunkwarning.PNG" alt="splunkwarning.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Mar 2022 04:54:10 GMT</pubDate>
    <dc:creator>derekho55</dc:creator>
    <dc:date>2022-03-18T04:54:10Z</dc:date>
    <item>
      <title>Why can I not expand lookup field due to a reference cycle in the lookup configuration?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/543455#M563</link>
      <description>&lt;P&gt;on Splunk Cloud (8.1.2101.1) I'm encountering a warning message in my search results - trying to figure out why this is popping up. Anybody have any idea what this message means and how to resolve it?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="splunkwarning.PNG" style="width: 685px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13279i69C213568EB60637/image-dimensions/685x77?v=v2" width="685" height="77" role="button" title="splunkwarning.PNG" alt="splunkwarning.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 04:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/543455#M563</guid>
      <dc:creator>derekho55</dc:creator>
      <dc:date>2022-03-18T04:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/544164#M569</link>
      <description>&lt;P&gt;Not an answer, but I am seeing the same problem with the 'user' field in wineventlog data. But if I change my search to use the Logon_Account field instead then I get the same results but without the warning. (Though Logon_Account is only present because I'm just looking at records where EventCode=4776.)&lt;/P&gt;&lt;P&gt;There does not seem to be any problem the results, it is only a warning and not an error. But I would like to know for sure what is causing it.&lt;/P&gt;&lt;P&gt;I should add, we are using Splunk Cloud 8.1.2101.2&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 18:50:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/544164#M569</guid>
      <dc:creator>threepointonefo</dc:creator>
      <dc:date>2021-03-18T18:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/544250#M571</link>
      <description>&lt;P&gt;Same issue here as well, which didn't occur until&amp;nbsp;&lt;SPAN&gt;8.1.2101.2. I haven't been able to find anything to indicate what may have caused the change in the release notes. So far it's only happened on one field, I'll see if I can find any other fields it's happening with and if there's a pattern there.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Edit: check out your automatic field lookups. I had one that was self-referential for some reason, and after fixing that I am no longer seeing the error.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 18:44:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/544250#M571</guid>
      <dc:creator>jmyers</dc:creator>
      <dc:date>2021-03-17T18:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/544251#M572</link>
      <description>&lt;P&gt;Do you have any automatic lookups involving the "action" field?&lt;BR /&gt;&lt;BR /&gt;I had one for the field I was having an issue with, and for some reason the lookup was self-referential. Once I fixed it (in my case, copied it in case deleting it caused problems, then deleted it), I no longer had the error.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 18:46:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/544251#M572</guid>
      <dc:creator>jmyers</dc:creator>
      <dc:date>2021-03-17T18:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/544391#M573</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229757"&gt;@jmyers&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I think you're right about the automatic lookups. I have this in the search log&lt;/P&gt;&lt;P&gt;03-18-2021 16:35:08.065 INFO SearchEvaluatorBasedExpander [20232 searchOrchestrator] - Performing lookup expansions&lt;BR /&gt;03-18-2021 16:35:08.065 WARN AutoLookupDriver [20232 searchOrchestrator] - Detected a cycle: fieldname=UserId, visitedFields=UserId,user&lt;BR /&gt;03-18-2021 16:35:08.065 WARN AutoLookupDriver [20232 searchOrchestrator] - sid:1616085307.16530 Cannot expand lookup field 'user' due to a reference cycle in the lookup configuration. Rewrite the lookup configuration to remove the reference cycle.&lt;/P&gt;&lt;P&gt;But I've yet to find the lookup that is causing the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 18:48:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/544391#M573</guid>
      <dc:creator>threepointonefo</dc:creator>
      <dc:date>2021-03-18T18:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/547777#M625</link>
      <description>&lt;P&gt;Right, this message was recently upgraded from DEBUG to WARN in order to surface the reference cycle issue that can slow down the search performance.&lt;/P&gt;&lt;P&gt;We are looking into whether we can make the message more actionable, but the other WARN message in search.log might be able to help locate the offending lookup(s). In this case, Splunk Software saw `user` field in the SPL, and figured that it could be mapped from `UserId` field through an automatic lookup. And `UserId` field itself could be mapped from `UserId` field itself, forming a reference cycle. So, most likely, there is a reference cycle like: UserId OUTPUT UserId, or, UserId_1 AS UserId OUTPUT UserId_2 AS UserId. Removing that cycle (which is not necessary) should get rid of the warning.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 17:50:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/547777#M625</guid>
      <dc:creator>rayl</dc:creator>
      <dc:date>2021-04-13T17:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/547900#M628</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233435"&gt;@rayl&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the background information. It helps to understand what's going on.&lt;BR /&gt;I no longer get the warning with the 'user' field in wineventlog data (I don't know why that problem has disappeared) but I do still get it on the 'UserId' field in office365.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;With office365 data I find that with the time picker set to 30 days searches on the 'UserId' field take a very long time and scan millions of events whereas searches on the 'user' field take only a second or two and scan just hundreds of events. The two field names reference the same data so it makes a good comparison. However with all the various lookups created by the add-ons it is not easy to find what is causing the problem. I really need to know the names of the lookups involved. Is there any way of getting that information?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 13:23:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/547900#M628</guid>
      <dc:creator>threepointonefo</dc:creator>
      <dc:date>2021-04-14T13:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/553380#M683</link>
      <description>&lt;P&gt;I found this issue myself, and some of the automatic lookups had things like:&lt;BR /&gt;&lt;BR /&gt;windows_action_lookup Type OUTPUTNEW action, action AS status&lt;/P&gt;&lt;P&gt;Resaving them then resolved them back to&amp;nbsp;&lt;BR /&gt;windows_action_lookup Type OUTPUTNEW action AS status&lt;/P&gt;&lt;P&gt;Which has then resolved the issue.&lt;BR /&gt;It appears that the Splunk_TA_Windows had these lookup issues, seems to work correctly as most entries had action fields in them anyway.&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 17:43:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/553380#M683</guid>
      <dc:creator>bwheel</dc:creator>
      <dc:date>2021-05-27T17:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/556130#M708</link>
      <description>&lt;P&gt;This worked for me - thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 07:35:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/556130#M708</guid>
      <dc:creator>heikothiel</dc:creator>
      <dc:date>2021-06-17T07:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/557686#M724</link>
      <description>&lt;P&gt;Had this issue with "user", it was due to the Salesforce App and Addon. You can update it to the latest version which fixes it.&lt;/P&gt;&lt;P&gt;The easiest way to find out the cause:&lt;/P&gt;&lt;P&gt;1. Run search that has the issue.&lt;/P&gt;&lt;P&gt;2. View Job -&amp;gt; Inspect Job&lt;/P&gt;&lt;P&gt;3. Click the link "search.log" in the Inspect Job windows.&lt;/P&gt;&lt;P&gt;3. Search the text for "cycle".&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 20:27:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/557686#M724</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2021-06-29T20:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/557790#M725</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190794"&gt;@johnhuang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your message. That explains why the problem with the 'user' field went away as I had updated the Salesforce App some time after finding the problem.&lt;BR /&gt;I still have the problem with 'UserId' in our Office 365 index though I can work around that by using the 'user' field which has the same data.&lt;BR /&gt;I too have been looking in search.log but I am unable to tell which lookup is causing the problem. I get "Reading schema for lookup table" for about every lookup we have and that is followed by:&lt;/P&gt;&lt;P&gt;06-30-2021 10:58:54.127 INFO SearchEvaluatorBasedExpander [14716 searchOrchestrator] - Performing lookup expansions&lt;BR /&gt;06-30-2021 10:58:54.128 WARN AutoLookupDriver [14716 searchOrchestrator] - Detected a cycle: fieldname=UserId, visitedFields=UserId&lt;BR /&gt;06-30-2021 10:58:54.128 WARN AutoLookupDriver [14716 searchOrchestrator] - sid:1625050733.210543 Cannot expand lookup field 'UserId' due to a reference cycle in the lookup configuration. Rewrite the lookup configuration to remove the reference cycle.&lt;/P&gt;&lt;P&gt;Is there a way to tell which lookup is causing the problem?&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233435"&gt;@rayl&lt;/a&gt;&amp;nbsp; says above that Splunk are looking into whether they can make the message more actionable but at present I can't see a way to identify the problem lookup.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 11:37:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/557790#M725</guid>
      <dc:creator>threepointonefo</dc:creator>
      <dc:date>2021-06-30T11:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/557820#M726</link>
      <description>&lt;P&gt;I have the same issue with a query&lt;/P&gt;&lt;DIV class="alerts search-searchflashmessages"&gt;&lt;DIV class="alert alert-warning"&gt;Cannot expand lookup field 'action' due to a reference cycle in the lookup configuration. Rewrite the lookup configuration to remove the reference cycle.&lt;DIV class="alert alert-warning"&gt;&amp;nbsp;&lt;DIV class="alert alert-warning"&gt;Can I have more information on what a reference cycle actually means and how to find it??? I think the terminology of this error message could be tweaked to provide more information other than "reference cycle"&lt;BR /&gt;&lt;BR /&gt;I am not querying windowseventlogs but actually querying firepower logs&amp;nbsp;&lt;DIV class="alert alert-warning"&gt;&amp;nbsp;&lt;DIV class="alert alert-warning"&gt;thanks in advance?&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 30 Jun 2021 14:20:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/557820#M726</guid>
      <dc:creator>radam2000</dc:creator>
      <dc:date>2021-06-30T14:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/557853#M727</link>
      <description>&lt;P&gt;The enhancement has been released in&amp;nbsp;&lt;SPAN&gt;8.2.2105, where a message in search.log would tell which exact lookups caused the reference cycle. Have your stack upgraded to that version if it hasn't been done.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 16:15:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/557853#M727</guid>
      <dc:creator>rayl</dc:creator>
      <dc:date>2021-06-30T16:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/559870#M741</link>
      <description>&lt;P&gt;Starting from 8.2.2, you can click on the "job", then "inspect job", then click on "search log" Do "Ctrl" Find; and type in "reference cycle", copy the highlighted texts into a notepad, and you can see the problematic lookup.&lt;BR /&gt;&lt;BR /&gt;You also do not need to re-save this lookup (It is the Automatic Lookup in most cases). The problem is because the Lookup input field and Lookup output field has blank fields. Delete these blanks (Click on the Automatic Lookup name, and then delete the blank field line under lookup input fields and lookup output field) and click save.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It should be resolved.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 19:57:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/559870#M741</guid>
      <dc:creator>Yemi_Splunk</dc:creator>
      <dc:date>2021-07-16T19:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/561015#M756</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236520"&gt;@Yemi_Splunk&lt;/a&gt;Thanks for your post on this. We are on Version: 8.2.2104.1&lt;/P&gt;&lt;P&gt;I've had a look at the logs again but I can't enough information to identify the lookup that is causing the problem.&lt;/P&gt;&lt;P&gt;The search that gives this error is searching for a specific UserId in Office 365 data. When I run the search I get the warning:&lt;/P&gt;&lt;P&gt;warn : &lt;SPAN class="text"&gt;Cannot expand lookup field 'UserId' due to a reference cycle in the lookup configuration. Rewrite the lookup configuration to remove the reference cycle. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And in search.log I get this:&lt;/P&gt;&lt;PRE&gt;07-27-2021 11:34:41.648 INFO  SearchEvaluatorBasedExpander [13577 searchOrchestrator] -  Performing lookup expansions
07-27-2021 11:34:41.648 WARN  AutoLookupDriver [13577 searchOrchestrator] - Detected a cycle: fieldname=UserId, visitedFields=UserId
07-27-2021 11:34:41.648 WARN  AutoLookupDriver [13577 searchOrchestrator] - sid:fe0545bbe5a575d7_tmp Cannot expand lookup field 'UserId' due to a reference cycle in the lookup configuration. Rewrite the lookup configuration to remove the reference cycle.
07-27-2021 11:34:41.648 INFO  SearchEvaluatorBasedExpander [13577 searchOrchestrator] -  Lookup expansion took 0 ms&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't see the name of the problem lookup. Am I missing something obvious or doing something wrong?&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233435"&gt;@rayl&lt;/a&gt;&amp;nbsp; I didn't see the post about 8.2.2105 until after I posted the above.&lt;/P&gt;&lt;P&gt;I eagerly await the update to our Splunk Cloud instance!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 13:40:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/561015#M756</guid>
      <dc:creator>threepointonefo</dc:creator>
      <dc:date>2021-07-27T13:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/561952#M1021</link>
      <description>&lt;P&gt;Thanks rayl&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am on splunk cloud version 8.2.2104.1 and am scheduled for upgrade on August 11th ... will have to wait for the upgrade to find it...&lt;/P&gt;&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 20:20:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/561952#M1021</guid>
      <dc:creator>radam2000</dc:creator>
      <dc:date>2021-08-03T20:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/563011#M1055</link>
      <description>&lt;P&gt;I have the same problem on my Splunk search head version 8.2.1 and it was resolved after the completion of below steps.&lt;/P&gt;&lt;P&gt;Error Messages: -&lt;/P&gt;&lt;P&gt;"Cannot expand lookup field '&lt;FONT color="#FF0000"&gt;action&lt;/FONT&gt;' due to a reference cycle in the lookup configuration. Check search .log for details and update the lookup configuration to remove the reference cycle."&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Log onto search head by putty, run below command.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;$SPLUNK_HOME/splunk btool props list --debug | grep -E 'LOOKUP.*\saction\s.*\saction\s'&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Result:-&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/apps/Splunk_TA_cisco-asa/default/props.conf&lt;FONT color="#FF0000"&gt; LOOKUP-cisco_asa_action_lookup_1 = cisco_asa_action_lookup vendor_action as action OUTPUT action, action AS Cisco_ASA_action&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Log onto to search head on web browser&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Go to `Settings` - `Lookups` - `Automatic lookups`.&lt;BR /&gt;4.&amp;nbsp; Look for a lookup named as `&lt;FONT color="#000000"&gt;LOOKUP-cisco_asa_action_lookup_1&lt;/FONT&gt;`.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sean_wong_0-1628733390535.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15538i3EE303EE202E862D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sean_wong_0-1628733390535.png" alt="sean_wong_0-1628733390535.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;p.s. The captured screen is showing the last result (problem was solved).&amp;nbsp; I have not regenerate the problem, please treat it as an example.&amp;nbsp;&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; Click on '&lt;FONT color="#FF0000"&gt;cisco:asa : LOOKUP-cisco_asa_action_lookup_1&lt;/FONT&gt;'.&lt;BR /&gt;6.&amp;nbsp; Upon opening the lookup in lookup editor, click `Save` without touching any field.&lt;BR /&gt;7.&amp;nbsp; Repeat the steps`1.` to `4.` if there is another lookup has same issue.&lt;BR /&gt;8. After the above, run the command again and the new lookups should look like as followings.&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/apps/Splunk_TA_cisco-asa/local/props.conf &lt;FONT color="#FF0000"&gt;LOOKUP-cisco_asa_action_lookup_1 = cisco_asa_action_lookup vendor_action AS action OUTPUT action AS Cisco_ASA_action&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;9.&amp;nbsp; Restart the search head once and see whether the problem is solved.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;Sean Wong&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 02:13:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/563011#M1055</guid>
      <dc:creator>sean_wong</dc:creator>
      <dc:date>2021-08-12T02:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/569033#M1117</link>
      <description>&lt;P&gt;Kindly review lookup -&amp;nbsp;&lt;STRONG&gt;sfdc:loginhistory : LOOKUP-SFDC-USER_NAME&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;I tried saving the lookup, but it dint help.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 02:15:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/569033#M1117</guid>
      <dc:creator>Saurabh_Goyal</dc:creator>
      <dc:date>2021-09-30T02:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/570781#M1141</link>
      <description>&lt;P&gt;Worked for me!&lt;/P&gt;&lt;P&gt;The issue is indeed with the add-on Splunk_TA_cisco_asa on default/props.conf.&lt;/P&gt;&lt;P&gt;This is what is should look like, but it's fixed by adding to local/props.conf:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;LOOKUP-cisco_asa_action_lookup_1 = cisco_asa_action_lookup vendor_action AS action OUTPUT action AS Cisco_ASA_action&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 13:42:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/570781#M1141</guid>
      <dc:creator>duartet</dc:creator>
      <dc:date>2021-10-13T13:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot expand lookup field due to a reference cycle in the lookup configuration.</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/573511#M1162</link>
      <description>&lt;P&gt;Well Done Sean, resolved my issue as well.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 17:39:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-reference-cycle-in/m-p/573511#M1162</guid>
      <dc:creator>walsborn</dc:creator>
      <dc:date>2021-11-03T17:39:08Z</dc:date>
    </item>
  </channel>
</rss>

