<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup missing definition in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-missing-definition/m-p/560403#M159258</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235920"&gt;@victornajduch&lt;/a&gt;&amp;nbsp; Similar issue has been answered here -&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Error-in-lookup-command-Cannot-find-the-source-field/m-p/557691" target="_blank"&gt;Solved: Error in 'lookup' command: Cannot find the source ... - Splunk Community&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jul 2021 23:43:07 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-07-21T23:43:07Z</dc:date>
    <item>
      <title>Lookup missing definition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-missing-definition/m-p/560393#M159255</link>
      <description>&lt;P&gt;Good afternoon,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't make sense of why I can't extract a definition from a particular csv.&amp;nbsp;&lt;BR /&gt;I doublechecked permissions and verified that all of my columns are appearing via&amp;nbsp;| inputlookup file.csv | table loopback, device&lt;BR /&gt;&lt;BR /&gt;the output recognizes both the custom device data as well as loopback but if I attempt to table the info "device" is not recognized.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;index=index "syslog message"&lt;BR /&gt;| rex field=_raw "peer (?&amp;lt;neighbor&amp;gt;\d+.\d+.\d+.\d+.)" | dedup neighbor&lt;/P&gt;&lt;P&gt;| lookup xo-access-loopback loopback as neighbor output device | table device, neighbor&lt;BR /&gt;&lt;BR /&gt;I get neighbor output but not device.&amp;nbsp;&lt;BR /&gt;csv looks like -&amp;nbsp;&lt;BR /&gt;Any ideas?&lt;/P&gt;&lt;TABLE width="272"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="208"&gt;device&lt;/TD&gt;&lt;TD width="64"&gt;loopback&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;routername&lt;/TD&gt;&lt;TD&gt;x.x.x.x&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 21 Jul 2021 20:36:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-missing-definition/m-p/560393#M159255</guid>
      <dc:creator>victornajduch</dc:creator>
      <dc:date>2021-07-21T20:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup missing definition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-missing-definition/m-p/560402#M159257</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235920"&gt;@victornajduch&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am hoping '&lt;SPAN&gt;neighbor' is correctly extracted. The lookup file could be sometimes having hidden chars not visible through normal text editors, you can try opening it using vi/vim/emacs editors to find and clear these chars.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and Accept&amp;nbsp; solution if this reply helps!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 23:40:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-missing-definition/m-p/560402#M159257</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-21T23:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup missing definition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-missing-definition/m-p/560403#M159258</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235920"&gt;@victornajduch&lt;/a&gt;&amp;nbsp; Similar issue has been answered here -&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Error-in-lookup-command-Cannot-find-the-source-field/m-p/557691" target="_blank"&gt;Solved: Error in 'lookup' command: Cannot find the source ... - Splunk Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 23:43:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-missing-definition/m-p/560403#M159258</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-21T23:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup missing definition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-missing-definition/m-p/560506#M159290</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;checked for special characters and added a 3 (superfluous) column. No change.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 17:11:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-missing-definition/m-p/560506#M159290</guid>
      <dc:creator>victornajduch</dc:creator>
      <dc:date>2021-07-22T17:11:09Z</dc:date>
    </item>
  </channel>
</rss>

