<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic After the Upgrade to 7.0.3 the inputlookup command not  working properly in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/After-the-Upgrade-to-7-0-3-the-inputlookup-command-not-working/m-p/457079#M100257</link>
    <description>&lt;P&gt;The lookup file was working fine for long time (2 months)  and contained 1000+ entries&lt;/P&gt;

&lt;P&gt;However, after upgrading to 7.0.3, it's not working properly. When run , most of the time throwing me errors like&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;unknown error&lt;BR /&gt;
The search job "1532509894.27177" was canceled remotely or expired.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;The search query when run will show that its parsing and after some time will endup with above error.&lt;/P&gt;

&lt;P&gt;index=wineventlog src_user!="&lt;EM&gt;$" EventCode=4725  user!="&lt;/EM&gt;$"  sourcetype="WinEventLog:Security"  [|inputlookup Disabled | fields user] | stats count by user&lt;/P&gt;

&lt;P&gt;When tried with lookup with lesser number of entries ( 40 entries) its working fine. But when the entries in the lookup go above 400+ , im getting  the error.&lt;/P&gt;

&lt;P&gt;Before upgrade, I was able to get the results even when i run  for all time range.&lt;/P&gt;

&lt;P&gt;Do we have any workaround on this issue.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jul 2018 09:42:18 GMT</pubDate>
    <dc:creator>renjujacob88</dc:creator>
    <dc:date>2018-07-25T09:42:18Z</dc:date>
    <item>
      <title>After the Upgrade to 7.0.3 the inputlookup command not  working properly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-the-Upgrade-to-7-0-3-the-inputlookup-command-not-working/m-p/457079#M100257</link>
      <description>&lt;P&gt;The lookup file was working fine for long time (2 months)  and contained 1000+ entries&lt;/P&gt;

&lt;P&gt;However, after upgrading to 7.0.3, it's not working properly. When run , most of the time throwing me errors like&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;unknown error&lt;BR /&gt;
The search job "1532509894.27177" was canceled remotely or expired.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;The search query when run will show that its parsing and after some time will endup with above error.&lt;/P&gt;

&lt;P&gt;index=wineventlog src_user!="&lt;EM&gt;$" EventCode=4725  user!="&lt;/EM&gt;$"  sourcetype="WinEventLog:Security"  [|inputlookup Disabled | fields user] | stats count by user&lt;/P&gt;

&lt;P&gt;When tried with lookup with lesser number of entries ( 40 entries) its working fine. But when the entries in the lookup go above 400+ , im getting  the error.&lt;/P&gt;

&lt;P&gt;Before upgrade, I was able to get the results even when i run  for all time range.&lt;/P&gt;

&lt;P&gt;Do we have any workaround on this issue.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 09:42:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-the-Upgrade-to-7-0-3-the-inputlookup-command-not-working/m-p/457079#M100257</guid>
      <dc:creator>renjujacob88</dc:creator>
      <dc:date>2018-07-25T09:42:18Z</dc:date>
    </item>
  </channel>
</rss>

