<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Could not load lookup=LOOKUP-user_account_control_property in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584567#M25252</link>
    <description>&lt;P&gt;I uninstalled the splunk_TA_windows app completely from the search head cluster, and deployed a clean install of the app(so no local directories anywhere). and am still seeing the error.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 17:37:19 GMT</pubDate>
    <dc:creator>TheBravoSierra</dc:creator>
    <dc:date>2022-02-10T17:37:19Z</dc:date>
    <item>
      <title>Why this error on search head cluster after updating Splunk_TA_Windows?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584353#M25250</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I recently updated Splunk_TA_Windows and am seeing this error on my search head cluster:&lt;BR /&gt;&lt;BR /&gt;[Indexers] Could not load lookup=LOOKUP-user_account_control_property&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This is an automatic lookup generated in the default directory of the app. I'm not familiar with it and am not seeing this error on my deployer(standalone) instance. The configs appear the same.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any help is greatly appreciated.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 17:40:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584353#M25250</guid>
      <dc:creator>TheBravoSierra</dc:creator>
      <dc:date>2022-02-10T17:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Could not load lookup=LOOKUP-user_account_control_property</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584437#M25251</link>
      <description>&lt;P&gt;It's a scripted lookup in the Windows Add-on. The default behavior of Splunk and in Windows Add-on is to put it as part of distributed search bundle.&lt;/P&gt;&lt;P&gt;So, it seems those settings (distributed search bundle related) have been changed in your environment. And SHC is not pushing the lookup and lookup script to the indexers.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/DistSearch/Knowledgebundlereplication" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.4/DistSearch/Knowledgebundlereplication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Distsearchconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Distsearchconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 06:16:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584437#M25251</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-02-10T06:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: Could not load lookup=LOOKUP-user_account_control_property</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584567#M25252</link>
      <description>&lt;P&gt;I uninstalled the splunk_TA_windows app completely from the search head cluster, and deployed a clean install of the app(so no local directories anywhere). and am still seeing the error.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 17:37:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584567#M25252</guid>
      <dc:creator>TheBravoSierra</dc:creator>
      <dc:date>2022-02-10T17:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Could not load lookup=LOOKUP-user_account_control_property</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584633#M25253</link>
      <description>&lt;P&gt;Use btool to search those attributes in the environment.&lt;/P&gt;&lt;P&gt;* $SPLUNK_HOME/bin/splunk btool distsearch list --debug&lt;/P&gt;&lt;P&gt;(To see what are the attributes set related to distributed search)&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 05:00:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584633#M25253</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-02-11T05:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why this error on search head cluster after updating Splunk_TA_Windows?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/695588#M28435</link>
      <description>&lt;P&gt;Solution/workaround was to comment out the user_account_control_property lines in the default transforms/props files.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 16:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/695588#M28435</guid>
      <dc:creator>TheBravoSierra</dc:creator>
      <dc:date>2024-08-07T16:50:17Z</dc:date>
    </item>
  </channel>
</rss>

