<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is my dashboard giving error for only one lookup ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/531626#M150150</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/97436"&gt;@ramarcsight&lt;/a&gt;&amp;nbsp;, I know its pretty old but just wanted to check if by any chance did you manage to resolve it? As I am facing similar issue now post upgrading environment to 8.1.X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 02 Dec 2020 04:11:31 GMT</pubDate>
    <dc:creator>bishtk</dc:creator>
    <dc:date>2020-12-02T04:11:31Z</dc:date>
    <item>
      <title>Why is my dashboard giving error for only one lookup ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/420871#M120935</link>
      <description>&lt;P&gt;Hello Everyone&lt;BR /&gt;
I have a dashboard and when i ran it, it gave the following error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[IDX01] Failed to re-open lookup file: /opt/splunk/var/run/searchpeers/1B9FREERF-50TY-4767-AH6Y-B567EGRYEH-1539009321/kvstore_s_MSS-T@HX1YtUhJKI87IUImcch_netapp_dezbGUbszQGAW242l@NpogZ9AS

[IDX02]Failed to re-open lookup file: /opt/splunk/var/run/searchpeers/1B9FREERF-50TY-4767-AH6Y-B567EGRYEH-1539009321/kvstore_s_MSS-T@HX1YtUhJKI87IUImcch_netapp_dezbGUbszQGAW242l@NpogZ9AS
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It gave the error for all the indexers.&lt;/P&gt;

&lt;P&gt;original search :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=foo 
  | lookup device_lookup device_id as id OUTPUT device_ip
  | fields device_ip , orgDeviceName
  | stats count by device_ip 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but when i run&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup device_lookup
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It works fine.&lt;/P&gt;

&lt;P&gt;weirdly all other lookups run without local=true. However, only this particular lookup gives error when the search job is run&lt;BR /&gt;
as&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[IDX02]Failed to re-open lookup file: /opt/splunk/var/run/searchpeers/1B9FREERF-50TY-4767-AH6Y-B567EGRYEH-1539009321/kvstore_s_MSS-T@HX1YtUhJKI87IUImcch_netapp_dezbGUbszQGAW242l@NpogZ9AS
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Please advise&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 12:54:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/420871#M120935</guid>
      <dc:creator>ramarcsight</dc:creator>
      <dc:date>2018-10-09T12:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my dashboard giving error for only one lookup ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/420872#M120936</link>
      <description>&lt;P&gt;Is it a KV-store lookup ?  Are all other lookups similar type or csv lookups?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 14:32:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/420872#M120936</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2018-10-09T14:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my dashboard giving error for only one lookup ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/420873#M120937</link>
      <description>&lt;P&gt;All are kvstore only &lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 14:49:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/420873#M120937</guid>
      <dc:creator>ramarcsight</dc:creator>
      <dc:date>2018-10-09T14:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my dashboard giving error for only one lookup ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/531626#M150150</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/97436"&gt;@ramarcsight&lt;/a&gt;&amp;nbsp;, I know its pretty old but just wanted to check if by any chance did you manage to resolve it? As I am facing similar issue now post upgrading environment to 8.1.X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 04:11:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/531626#M150150</guid>
      <dc:creator>bishtk</dc:creator>
      <dc:date>2020-12-02T04:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my dashboard giving error for only one lookup ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/538124#M152111</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/193398"&gt;@bishtk&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/97436"&gt;@ramarcsight&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Had the same "&lt;EM&gt;Failed to re-open lookup file&lt;/EM&gt;" issue with few KVStore lookups.&lt;/P&gt;&lt;P&gt;Found some "&lt;STRONG&gt;.index.lock&lt;/STRONG&gt;" artifacts for the lookups having the issue, using this search:&lt;BR /&gt;&lt;BR /&gt;| rest splunk_server=local /servicesNS/-/-/configs/conf-lookups search="*"&lt;BR /&gt;| search title="*"&lt;BR /&gt;| eval title=if(like(title,"*"),null,title)&lt;BR /&gt;| dedup title&lt;BR /&gt;| rename eai:acl.app as app, eai:acl.perms.read as read, eai:acl.sharing as sharing&lt;BR /&gt;| fields - updated published id eai*&lt;BR /&gt;| rename title as stanza&lt;BR /&gt;| search stanza="*&lt;STRONG&gt;lock&lt;/STRONG&gt;"&lt;BR /&gt;| table stanza&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 16:57:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/538124#M152111</guid>
      <dc:creator>Laszlo_K</dc:creator>
      <dc:date>2021-02-01T16:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my dashboard giving error for only one lookup ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/568216#M198011</link>
      <description>&lt;P&gt;This might help&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/Fixedissues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/Fixedissues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 10:08:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-dashboard-giving-error-for-only-one-lookup/m-p/568216#M198011</guid>
      <dc:creator>dmadeira_splunk</dc:creator>
      <dc:date>2021-09-23T10:08:02Z</dc:date>
    </item>
  </channel>
</rss>

