<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External lookups: lookup not found error in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52673#M12814</link>
    <description>&lt;P&gt;Done... yes the lookup stanza is there.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Sep 2010 04:45:06 GMT</pubDate>
    <dc:creator>twinspop</dc:creator>
    <dc:date>2010-09-21T04:45:06Z</dc:date>
    <item>
      <title>External lookups: lookup not found error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52669#M12810</link>
      <description>&lt;P&gt;I'm following the instructions &lt;A href="http://www.splunk.com/base/Documentation/latest/Knowledge/Addfieldsfromexternaldatasources#Set_up_a_fields_lookup_based_on_an_external_command_or_script" rel="nofollow"&gt;here&lt;/A&gt; and can't get it to even recognize the lookup. Did I miss something?&lt;/P&gt;

&lt;P&gt;My transforms.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[SUBJDECODE]
external_cmd = utfconv.py Subject
fields_list = Subject
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;My props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::/syslog/mail/*]
LOOKUP_table = SUBJDECODE Subject
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any search gives me the error: "The lookup table 'SUBJDECODE' does not exist. It is referenced by configuration 'source::/syslog/mail/*'."&lt;/P&gt;

&lt;P&gt;I've even verified the lookup exists through the GUI -&amp;gt; Manager -&amp;gt; Lookups -&amp;gt; Lookup Defs&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;SUBJDECODE   external   No owner   system   Global | Permissions   Enabled ....
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It appears to recognize the props file, but is not fully integrating the transforms stanza. It shows in the GUI manager but can't be used. Both conf files are in $splunk/etc/system/local, but I've also tried them in the $splunk/etc/apps/search/local dir with equivalent results.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2010 04:03:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52669#M12810</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2010-09-17T04:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: External lookups: lookup not found error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52670#M12811</link>
      <description>&lt;P&gt;Despite not being in the docs, I've added the metadata stanza (export=system). The stanza was already in the search app metadata. However, it was not in the system metadata file. I've added there also. Still no go. Anyone? Buehler?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Sep 2010 04:39:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52670#M12811</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2010-09-18T04:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: External lookups: lookup not found error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52671#M12812</link>
      <description>&lt;P&gt;Now with shiny, new, strong, faster, better 4.1.5. Problem persists. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Sep 2010 05:21:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52671#M12812</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2010-09-18T05:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: External lookups: lookup not found error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52672#M12813</link>
      <description>&lt;P&gt;it might be an issue with your permissions? you can run: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk cmd btool transforms list --user=&amp;lt;user-running-search&amp;gt; --app=search --debug
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and if it doesn't list the SUBJDECODE stanza, then it's a permissions issue w/ that particular user...&lt;/P&gt;</description>
      <pubDate>Sat, 18 Sep 2010 06:39:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52672#M12813</guid>
      <dc:creator>sophy</dc:creator>
      <dc:date>2010-09-18T06:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: External lookups: lookup not found error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52673#M12814</link>
      <description>&lt;P&gt;Done... yes the lookup stanza is there.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2010 04:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52673#M12814</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2010-09-21T04:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: External lookups: lookup not found error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52674#M12815</link>
      <description>&lt;P&gt;A few other things you may want to check here :&lt;/P&gt;

&lt;P&gt;1) Where is the "utconfv.py" script located? As transforms.conf.spec states :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;external_cmd = &amp;lt;string&amp;gt;
* Command and arguments to invoke to perform lookups.
* This string is parsed like a shell command.
* The first argument is expected to be a python script located in $SPLUNK_HOME/etc/&amp;lt;app_name&amp;gt;/bin (or ../etc/searchscripts) &amp;lt;=========
* Presence of this field indicates that lookup is external command based.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;2) Are there no permission/ownership issues with utconf.py?&lt;/P&gt;

&lt;P&gt;3) Check in $SPLUNK_HOME/var/log/splunk/python.log for errors referencing your lookup script.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2010 07:23:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52674#M12815</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2010-09-21T07:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: External lookups: lookup not found error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52675#M12816</link>
      <description>&lt;P&gt;The script is in $SPLUNK/etc/searchscripts and is set to 755. The python.log file is empty.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2010 21:24:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52675#M12816</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2010-09-21T21:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: External lookups: lookup not found error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52676#M12817</link>
      <description>&lt;P&gt;OK, I copied the dnslookup stanza from etc/system/default/transforms.conf and put it into local/transforms.conf. I named it dnslookup2. That works. So external lookups do work, but my custom command isn't working. That leads me to believe the error is with my script. If so, the error message provided is terribly misleading.&lt;/P&gt;

&lt;P&gt;As for the script, running on the command line works fine. Piping CSV data into STDIN with the required args results in CSV being spit back out.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2010 21:55:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52676#M12817</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2010-09-21T21:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: External lookups: lookup not found error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52677#M12818</link>
      <description>&lt;P&gt;The stanza for the external lookup was not correct. The docs are ambiguous in a few places, and the absolutely terrible error message sent me on a wild goose chase, but I think I finally got there.&lt;/P&gt;

&lt;P&gt;In transforms.conf you need to list the name of the field that will be handed to the lookup &lt;EM&gt;AS WELL AS&lt;/EM&gt; the field name you want the script to output post-lookup. So:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[SUBJDECODE]
external_cmd = utfconv.py Subject decoded_subject
fields_list = Subject, decoded_subject
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Even though decoded_subject doesn't exist, it needs to be there. I guess. Maybe. Anyway, it's working for me now. In my original stanza I was attempting to replace the original Subject field with the new value-- apparently a NOOP that blows up the logic and returns a completely unrelated error message.&lt;/P&gt;

&lt;P&gt;To call the lookup, you need to leave off the output field (apparently):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source=*mail* | lookup SUBJDECODE Subject
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Tada. It worked.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2010 23:06:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookups-lookup-not-found-error/m-p/52677#M12818</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2010-09-21T23:06:47Z</dc:date>
    </item>
  </channel>
</rss>

