<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: lookup table does not exist in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414378#M119389</link>
    <description>&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Can you provide the Splunk search you used?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Do you have necessary access to the lookup file?&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Fri, 26 Jul 2019 06:24:37 GMT</pubDate>
    <dc:creator>jawaharas</dc:creator>
    <dc:date>2019-07-26T06:24:37Z</dc:date>
    <item>
      <title>lookup table does not exist</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414377#M119388</link>
      <description>&lt;P&gt;I am having an issue where anyone that does a splunk search gets the following error:&lt;/P&gt;

&lt;P&gt;The lookup table 'event_id_to_action_lookup' does not exist. It is referenced by configuration 'MSExchange:2013:MessageTracking'&lt;/P&gt;

&lt;P&gt;I would be most obliged for any insight that anyone would be able to provide about this issue.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:30:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414377#M119388</guid>
      <dc:creator>gl0balt3kkie</dc:creator>
      <dc:date>2020-09-30T01:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table does not exist</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414378#M119389</link>
      <description>&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Can you provide the Splunk search you used?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Do you have necessary access to the lookup file?&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 26 Jul 2019 06:24:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414378#M119389</guid>
      <dc:creator>jawaharas</dc:creator>
      <dc:date>2019-07-26T06:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table does not exist</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414379#M119390</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196889"&gt;@gl0balt3kkie&lt;/a&gt;, the automatic lookup file is most likely missing from your splunk server i.e. it may not be on disk anymore. Either an app search/splunk collections were not enabled again. At times the lookup file maybe removed from a splunk version/app upgrade, usually the latter, but it's best to check if it's on disk manually.&lt;/P&gt;

&lt;P&gt;You can find where the lookup file is located by checking the lookup definition, followed by the file itself, on the UI. Simply navigate to...&lt;/P&gt;

&lt;P&gt;UI &amp;gt; Settings &amp;gt; Lookups &amp;gt; Lookup definitions &amp;gt; Select "All" for App Context &amp;gt; Select Owner as "Any" &amp;gt; Enter "event_id_to_action_lookup" in the search filter and hit find.&lt;/P&gt;

&lt;P&gt;Once you see the lookup filename, then you can navigate to...&lt;/P&gt;

&lt;P&gt;UI &amp;gt; Settings &amp;gt; Lookups &amp;gt; Lookup table files &amp;gt; Select "All" for App Context &amp;gt; Select Owner as "Any" &amp;gt;  Enter "event_id_to_action_lookup.csv" (if it is the same filename) in the search filter and hit find.&lt;/P&gt;

&lt;P&gt;You will see the folder path for the lookup file.&lt;/P&gt;

&lt;P&gt;The actual "event_id_to_action_lookup.csv" lookup file is part of the "TA-Exchange-Mailbox" app (TA-Exchange-Mailbox/lookups folder) which can be found here if you download "Splunk Add-on for Microsoft Exchange" app.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3225/" target="_blank"&gt;https://splunkbase.splunk.com/app/3225/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If this file is missing from your search head, you will need to import it back.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414379#M119390</guid>
      <dc:creator>rjteh_splunk</dc:creator>
      <dc:date>2020-09-30T01:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table does not exist</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414380#M119391</link>
      <description>&lt;P&gt;ok, thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 18:34:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414380#M119391</guid>
      <dc:creator>gl0balt3kkie</dc:creator>
      <dc:date>2019-07-31T18:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table does not exist</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414381#M119392</link>
      <description>&lt;P&gt;When I do a search at UI &amp;gt; Settings &amp;gt; Lookups &amp;gt; Lookup Definitions and ALL and ANY I get the following:&lt;BR /&gt;
"There are no configurations of this type. Click the "New" button to create a new configuration."&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 18:40:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414381#M119392</guid>
      <dc:creator>gl0balt3kkie</dc:creator>
      <dc:date>2019-07-31T18:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table does not exist</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414382#M119393</link>
      <description>&lt;P&gt;Do you have any lookup files in the "UI &amp;gt; Settings &amp;gt; Lookups &amp;gt; Lookup table files" section?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 18:44:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414382#M119393</guid>
      <dc:creator>rjteh_splunk</dc:creator>
      <dc:date>2019-07-31T18:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table does not exist</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414383#M119394</link>
      <description>&lt;P&gt;Yes, quite a few. However, I get the same message as above when I do a search for : event_id_to_action_lookup&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:34:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-does-not-exist/m-p/414383#M119394</guid>
      <dc:creator>gl0balt3kkie</dc:creator>
      <dc:date>2020-09-30T01:34:07Z</dc:date>
    </item>
  </channel>
</rss>

