<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dashboard in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Dashboard/m-p/757329#M120125</link>
    <description>&lt;P&gt;Hey all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running into an issue on one of my dashboards. The issue in questions states "could not load lookup= LOOKUP - user_account_control_property. This issue is persisting across multiple queries within the given dashboard. A previous thread stated to comment out user_account_control_property in default/transforms and prop files. I don't know where those are located. Thanks for helping a Splunk newb.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I tried to edit the entry for this lookup in the "Automatic Lookups" but that remedy the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jan 2026 23:07:21 GMT</pubDate>
    <dc:creator>808antwon</dc:creator>
    <dc:date>2026-01-14T23:07:21Z</dc:date>
    <item>
      <title>Dashboard</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Dashboard/m-p/757329#M120125</link>
      <description>&lt;P&gt;Hey all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running into an issue on one of my dashboards. The issue in questions states "could not load lookup= LOOKUP - user_account_control_property. This issue is persisting across multiple queries within the given dashboard. A previous thread stated to comment out user_account_control_property in default/transforms and prop files. I don't know where those are located. Thanks for helping a Splunk newb.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I tried to edit the entry for this lookup in the "Automatic Lookups" but that remedy the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 23:07:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Dashboard/m-p/757329#M120125</guid>
      <dc:creator>808antwon</dc:creator>
      <dc:date>2026-01-14T23:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Dashboard/m-p/757340#M120127</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315156"&gt;@808antwon&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;this lookup is in the Splunk_TA_Windows add-on.&lt;/P&gt;&lt;P&gt;at this url, &lt;A href="https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584567" target="_blank"&gt;https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-updating-Splunk-TA/m-p/584567&lt;/A&gt;&amp;nbsp;you can find a solution/workaround to your issue.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2026 08:09:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Dashboard/m-p/757340#M120127</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2026-01-15T08:09:06Z</dc:date>
    </item>
  </channel>
</rss>

