<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup table is invalid: Extra Commas? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47602#M11368</link>
    <description>&lt;P&gt;I have run into the same issue before on a "simple" lookup table having only 2 fields and also had trouble finding the issue.  This is what I did:&lt;/P&gt;

&lt;P&gt;1- search for line break at the end of the line&lt;BR /&gt;
2- search for lines not matching pattern "your data", "your data"  such as a line with only 1 value or no value; sometimes Excel torques an innocent csv file and therefore, I try to do a quick eyeball check in my favorite text editor&lt;BR /&gt;
3- check the limits.conf under the stanza "lookup" to see if it is a size violation&lt;/P&gt;

&lt;P&gt;Wish you success!&lt;/P&gt;</description>
    <pubDate>Wed, 15 May 2013 13:41:43 GMT</pubDate>
    <dc:creator>barakreeves</dc:creator>
    <dc:date>2013-05-15T13:41:43Z</dc:date>
    <item>
      <title>Lookup table is invalid: Extra Commas?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47598#M11364</link>
      <description>&lt;P&gt;I have a lookup table that I am getting an invalid error on. I believe its because there are extra commas in the data. The lookup table is two fields: codes and descriptions. The descriptions naturally have some commas in them. Is it possible that this is causing the invalid table error? If so, can I create custom regex for this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2013 20:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47598#M11364</guid>
      <dc:creator>aapittts</dc:creator>
      <dc:date>2013-02-28T20:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup table is invalid: Extra Commas?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47599#M11365</link>
      <description>&lt;P&gt;I tried throwing extra commas in one of my lookups but it did not throw a error, it just messed up the data that the lookup provided. &lt;/P&gt;

&lt;P&gt;Try putting text qualifiers "" around your fields like this&lt;/P&gt;

&lt;P&gt;"item1", "some text with a , in it"&lt;BR /&gt;
"item2", "another text with 2 ,, "&lt;/P&gt;

&lt;P&gt;This will allow it to ignore commas that are part of the description&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2013 21:16:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47599#M11365</guid>
      <dc:creator>cramasta</dc:creator>
      <dc:date>2013-02-28T21:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup table is invalid: Extra Commas?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47600#M11366</link>
      <description>&lt;P&gt;My issue wasn't commas but this is good to know.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2013 21:32:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47600#M11366</guid>
      <dc:creator>aapittts</dc:creator>
      <dc:date>2013-02-28T21:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup table is invalid: Extra Commas?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47601#M11367</link>
      <description>&lt;P&gt;@aapitts What was your issue then? I am running into the same problem.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2013 09:20:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47601#M11367</guid>
      <dc:creator>fu8R5juiNP64AKI</dc:creator>
      <dc:date>2013-05-15T09:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup table is invalid: Extra Commas?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47602#M11368</link>
      <description>&lt;P&gt;I have run into the same issue before on a "simple" lookup table having only 2 fields and also had trouble finding the issue.  This is what I did:&lt;/P&gt;

&lt;P&gt;1- search for line break at the end of the line&lt;BR /&gt;
2- search for lines not matching pattern "your data", "your data"  such as a line with only 1 value or no value; sometimes Excel torques an innocent csv file and therefore, I try to do a quick eyeball check in my favorite text editor&lt;BR /&gt;
3- check the limits.conf under the stanza "lookup" to see if it is a size violation&lt;/P&gt;

&lt;P&gt;Wish you success!&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2013 13:41:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-is-invalid-Extra-Commas/m-p/47602#M11368</guid>
      <dc:creator>barakreeves</dc:creator>
      <dc:date>2013-05-15T13:41:43Z</dc:date>
    </item>
  </channel>
</rss>

