<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to fix &amp;quot;Could not load lookup=LOOKUP-app_proto&amp;quot;? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467622#M131606</link>
    <description>&lt;P&gt;When you create a lookup definition at splunk, you have to run a command at splunk, to refresh the new configuration, because sometimes splunk does not recognise the new configuration. there two ways to do it&lt;BR /&gt;
1 - run the command debug refresh, this commando will make splunk to get the new lookup definition, this happened with myself several times. I am only able to get the lookup working properly after I run this process. It does not restart the splunk service, only reload the configuration definitions.&lt;BR /&gt;
-&amp;gt; &lt;A href="http://servername:8000/en-GB/debug/refresh"&gt;http://servername:8000/en-GB/debug/refresh&lt;/A&gt;&lt;BR /&gt;
2 - restart the splunk service &lt;/P&gt;

&lt;P&gt;Remember that all the configuration for the lookup definitions have to be done before you run this command.&lt;BR /&gt;
Here is a link to document about lookup files -&amp;gt; &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.2/Knowledge/Addfieldsfromexternaldatasources"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.2/Knowledge/Addfieldsfromexternaldatasources&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Oct 2019 00:53:09 GMT</pubDate>
    <dc:creator>ivanreis</dc:creator>
    <dc:date>2019-10-16T00:53:09Z</dc:date>
    <item>
      <title>How to fix "Could not load lookup=LOOKUP-app_proto"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467618#M131602</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;BR /&gt;
I keep getting the error message "Could not load lookup=LOOKUP-app_proto" in multiple apps on multiple dashboards. I have checked settings and neither the lookup file or definition existed and I can't figure out what is asking for this lookup. I can't find a reference to a lookup by that name in any documentation or on any of the Splunk sites.  I have created a lookup with a matching name but I don't know where to put it. I added it to the search app but I still got the error, then I added it to an app getting the error and that didn't work either. Basic system info is below, let me know what other info you would like and I will provide it as soon as I can. Thanks for reading.&lt;/P&gt;

&lt;P&gt;Stand-alone Splunk Enterprise&lt;BR /&gt;
Version: 7.3.0&lt;BR /&gt;
Build: 657388c7a488&lt;BR /&gt;
CIM: 4.13.0&lt;/P&gt;

&lt;P&gt;Apps: (Not all apps listed)&lt;BR /&gt;
InfoSec App for Splunk (getting error on some dashboards)&lt;BR /&gt;
Network Traffic App for Splunk (not getting the error)&lt;BR /&gt;
Cisco Security Suite (getting error on all dashboards)&lt;BR /&gt;
Obelisk Threat Intel (getting error on all "Splash" page dashboards)&lt;BR /&gt;
Splunk Security Essentials (getting error on "app awareness" dashboards)&lt;BR /&gt;
Splunk Stream (getting error on all informational dashboards)&lt;BR /&gt;
Firegen for Cisco ASA (getting error on all summary page dashboards)&lt;BR /&gt;
Cisco Firepower App for Splunk (getting error on all default dashboards)&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 18:06:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467618#M131602</guid>
      <dc:creator>eliasit</dc:creator>
      <dc:date>2019-09-03T18:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Could not load lookup=LOOKUP-app_proto"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467619#M131603</link>
      <description>&lt;P&gt;@eliasit - Did you check under Seetings-&amp;gt;lookup-&amp;gt;automatic lookup.  Is the lookup present there , probably the permissions are not correct, that is why you are seeing the error.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 18:33:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467619#M131603</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2019-09-03T18:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Could not load lookup=LOOKUP-app_proto"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467620#M131604</link>
      <description>&lt;P&gt;@Vijeta &lt;BR /&gt;
Sorry this reply is a week late. I didn't get a notification about your reply.&lt;/P&gt;

&lt;P&gt;There are no automatic lookups listed.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 20:21:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467620#M131604</guid>
      <dc:creator>eliasit</dc:creator>
      <dc:date>2019-09-10T20:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Could not load lookup=LOOKUP-app_proto"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467621#M131605</link>
      <description>&lt;P&gt;@Vijeta&lt;BR /&gt;
Looking back at my reply I realize my response was incomplete.&lt;BR /&gt;
There are no automatic lookups listed under that name (LOOKUP-app_proto). &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 00:24:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467621#M131605</guid>
      <dc:creator>eliasit</dc:creator>
      <dc:date>2019-10-16T00:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Could not load lookup=LOOKUP-app_proto"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467622#M131606</link>
      <description>&lt;P&gt;When you create a lookup definition at splunk, you have to run a command at splunk, to refresh the new configuration, because sometimes splunk does not recognise the new configuration. there two ways to do it&lt;BR /&gt;
1 - run the command debug refresh, this commando will make splunk to get the new lookup definition, this happened with myself several times. I am only able to get the lookup working properly after I run this process. It does not restart the splunk service, only reload the configuration definitions.&lt;BR /&gt;
-&amp;gt; &lt;A href="http://servername:8000/en-GB/debug/refresh"&gt;http://servername:8000/en-GB/debug/refresh&lt;/A&gt;&lt;BR /&gt;
2 - restart the splunk service &lt;/P&gt;

&lt;P&gt;Remember that all the configuration for the lookup definitions have to be done before you run this command.&lt;BR /&gt;
Here is a link to document about lookup files -&amp;gt; &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.2/Knowledge/Addfieldsfromexternaldatasources"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.2/Knowledge/Addfieldsfromexternaldatasources&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 00:53:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467622#M131606</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2019-10-16T00:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Could not load lookup=LOOKUP-app_proto"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467623#M131607</link>
      <description>&lt;P&gt;&lt;EM&gt;comment converted to answer&lt;BR /&gt;
**SOLUTION&lt;/EM&gt;&lt;BR /&gt;
I found the culprit, it was the Splunk Stream app.&lt;/P&gt;

&lt;P&gt;Searching automatic lookups for "*LOOKUP-app_proto" shows 10 auto lookups. Here are the first 3. The other 7 follow the same format. (stream:XXX : LOOKUP-app_proto)&lt;/P&gt;

&lt;P&gt;stream:dhcp : LOOKUP-app_proto&lt;BR /&gt;
stream:dns : LOOKUP-app_proto&lt;BR /&gt;
stream:http : LOOKUP-app_proto&lt;/P&gt;

&lt;P&gt;Searching both "Settings-&amp;gt;lookup-&amp;gt;Lookup table file" and "Settings-&amp;gt;lookup-&amp;gt;Lookup definitions" for the same string (*LOOKUP-app_proto) returns no results.&lt;/P&gt;

&lt;P&gt;Looking at these auto lookups, they list the "lookup definition" as stream_app_lookup, checking there showed "stream_app_lookup" was present but listed "supported fields" as none. Next, I checked the Lookup table files and found that "stream_app_lookup" was not present. (This should have been created when the Stream app was installed.)&lt;/P&gt;

&lt;P&gt;Searching the splunk directory for "*app_lookup.csv" showed the file in Splunk\etc\apps\splunk_app_stream\install\Splunk_TA_stream\lookups\&lt;/P&gt;

&lt;P&gt;I created a new lookup table file using the name "stream_app_lookup" and the found file. I set the app as "splunk_app_stream" and the permissions as global.&lt;/P&gt;

&lt;P&gt;The error has stopped.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:35:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/467623#M131607</guid>
      <dc:creator>eliasit</dc:creator>
      <dc:date>2020-09-30T02:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Could not load lookup=LOOKUP-app_proto"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/510741#M142968</link>
      <description>&lt;P&gt;I had the same error, but a different fix.&lt;/P&gt;&lt;P&gt;I had actually created a lookup with same name as an existing lookup, but with different fields. This name collision was causing the error. I changed the name of the new lookup and the errors went away.&lt;/P&gt;&lt;P&gt;I honestly wouldn't have found my issue if it wasn't for this thread.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 21:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/510741#M142968</guid>
      <dc:creator>dmccormack</dc:creator>
      <dc:date>2020-07-23T21:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Could not load lookup=LOOKUP-app_proto"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/518457#M145796</link>
      <description>&lt;P&gt;There can be another issue which might cause this error, the issue is explained below. If you mess up with input and output lookup fields then it can result in the same error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, consider a sample lookup file with fields: mac_id&amp;nbsp; and the same field in events is mac_orig.&lt;/P&gt;&lt;P&gt;mac_id = mac_orig&lt;/P&gt;&lt;P&gt;and this should show up in lookup definition as:&lt;/P&gt;&lt;P&gt;mac_id as mac_orig,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this order is reversed then the above error is seen.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 13:55:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/518457#M145796</guid>
      <dc:creator>behlkush</dc:creator>
      <dc:date>2020-09-08T13:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix "Could not load lookup=LOOKUP-app_proto"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/557971#M158466</link>
      <description>&lt;P&gt;&lt;SPAN&gt;hey eliasit,&lt;BR /&gt;can you suggest some inputs in integrating&amp;nbsp;the splunk_app_stream to get the dns logs, seems its not fetching&amp;nbsp;the data from dns servers when I tried installing splfwdrs in dns server via deployment server.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 04:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-fix-quot-Could-not-load-lookup-LOOKUP-app-proto-quot/m-p/557971#M158466</guid>
      <dc:creator>chandrabangaru</dc:creator>
      <dc:date>2021-07-01T04:23:55Z</dc:date>
    </item>
  </channel>
</rss>

