<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why our lookup that is updated by &amp;quot;outputlookup append=true&amp;quot; missing data added from the last 2 months? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341641#M101244</link>
    <description>&lt;P&gt;so if you do an inputlookup do you see the data from late 2016???&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/SearchReference/Inputlookup"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.1/SearchReference/Inputlookup&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jun 2017 21:51:57 GMT</pubDate>
    <dc:creator>mattymo</dc:creator>
    <dc:date>2017-06-09T21:51:57Z</dc:date>
    <item>
      <title>How to troubleshoot why our lookup that is updated by "outputlookup append=true" missing data added from the last 2 months?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341638#M101241</link>
      <description>&lt;P&gt;We have small lookup updated in search by &lt;CODE&gt;outputlookup append=true&lt;/CODE&gt;&lt;BR /&gt;
This is a SMALL size&lt;BR /&gt;
Our users noticed the lookup lost the added data from the last 2 months.&lt;BR /&gt;
Any clue?&lt;BR /&gt;
We have a search head and indexer cluster.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 20:34:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341638#M101241</guid>
      <dc:creator>Chamrong</dc:creator>
      <dc:date>2017-06-09T20:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why our lookup that is updated by "outputlookup append=true" missing data added from the last 2 months?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341639#M101242</link>
      <description>&lt;P&gt;Hi chamrong! any chance someone did an outputlookup without append and blew it away?&lt;/P&gt;

&lt;P&gt;you could search &lt;CODE&gt;index=_internal&lt;/CODE&gt; for your lookup name to see if you can identify any searches that may have overwritten it in the search or audit logs...&lt;/P&gt;

&lt;P&gt;is it a scheduled search that populates this ?&lt;/P&gt;

&lt;P&gt;whats the earliest date you have in the lookup?&lt;/P&gt;

&lt;P&gt;As long as you have the data still, you can simply run a search that covers the span of the missing data and rebuild the lookup file....&lt;/P&gt;

&lt;P&gt;Be sure to check &lt;CODE&gt;| inputlookup &amp;lt;yourLookupFile&amp;gt;&lt;/CODE&gt; to verify the users claims!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 21:07:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341639#M101242</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-06-09T21:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why our lookup that is updated by "outputlookup append=true" missing data added from the last 2 months?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341640#M101243</link>
      <description>&lt;P&gt;Hey Matt!! Thank for help.&lt;BR /&gt;
It is a schedule search happened daily.&lt;BR /&gt;
The earliest is late 2016&lt;BR /&gt;
The content is coming from the log of certain session&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 21:25:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341640#M101243</guid>
      <dc:creator>Chamrong</dc:creator>
      <dc:date>2017-06-09T21:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why our lookup that is updated by "outputlookup append=true" missing data added from the last 2 months?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341641#M101244</link>
      <description>&lt;P&gt;so if you do an inputlookup do you see the data from late 2016???&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/SearchReference/Inputlookup"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.1/SearchReference/Inputlookup&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 21:51:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341641#M101244</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-06-09T21:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why our lookup that is updated by "outputlookup append=true" missing data added from the last 2 months?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341642#M101245</link>
      <description>&lt;P&gt;Is it adding new data again since your users brought it to your attention?  or is it still broken?  If it's still broken, can you run the search manually w/o the outputlookup to see if there are still results?&lt;/P&gt;

&lt;P&gt;Also, if it's still broken, is the owner of the saved search still a valid Splunk user?  That's a long shot, but I think we've run into it before - user leaves company -&amp;gt; account terminated -&amp;gt; searches stop running (there would be errors in _internal)&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2017 13:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341642#M101245</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2017-06-10T13:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why our lookup that is updated by "outputlookup append=true" missing data added from the last 2 months?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341643#M101246</link>
      <description>&lt;P&gt;Start by checking the output from a single night, see whether it is really appending.  &lt;/P&gt;

&lt;P&gt;Also, start by checking whether the search that appends the data is running afoul of any subsearch limitations during the intermediate steps.&lt;/P&gt;

&lt;P&gt;Then backtrack 1 month at a time, see what the daily jobs were reporting, what errors may have cropped up.  &lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2017 19:52:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341643#M101246</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-06-11T19:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why our lookup that is updated by "outputlookup append=true" missing data added from the last 2 months?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341644#M101247</link>
      <description>&lt;P&gt;We find the root cause. the bulde pushout to the search head by the apps upgreade. To prevent this, we need to add -preserve-lookups true&lt;/P&gt;

&lt;P&gt;[5:00] &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.0/DistSearch/PropagateSHCconfigurationchanges#Maintain_lookup_files_across_app_upgrades"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.0/DistSearch/PropagateSHCconfigurationchanges#Maintain_lookup_files_across_app_upgrades&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 21:02:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-troubleshoot-why-our-lookup-that-is-updated-by-quot/m-p/341644#M101247</guid>
      <dc:creator>Chamrong</dc:creator>
      <dc:date>2017-06-16T21:02:37Z</dc:date>
    </item>
  </channel>
</rss>

