<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup Table Problem in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74579#M18798</link>
    <description>&lt;P&gt;@linu1988 It looks like this lookup table is private, based on the file location.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2013 23:21:28 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2013-06-25T23:21:28Z</dc:date>
    <item>
      <title>Lookup Table Problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74577#M18796</link>
      <description>&lt;P&gt;Hi, I have a problem when using lookup function in Splunk.&lt;/P&gt;

&lt;P&gt;I am using a lookup table in &lt;CODE&gt;C:\Program Files\Splunk\etc\users\admin\MyApp\lookups\lookuptable.csv&lt;/CODE&gt; and Lookup table name is "lookuptable"&lt;BR /&gt;
But if I want to add or change some data into lookuptable.csv&lt;/P&gt;

&lt;P&gt;when I search "| inputlookup lookuptable", I get the following error&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;File 'C:\Program Files\Splunk\etc\users\admin\MyApp\lookups\lookuptable.csv' could not be opened for reading.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I am wondering if anyone can help. Thanks a lot.&lt;/P&gt;

&lt;P&gt;PS, Can anyone tell me when I import lookuptable.csv into Splunk, why &lt;CODE&gt;C:\Program Files\Splunk\etc\users\admin\MyApp\lookups\lookuptable.csv&lt;/CODE&gt; have a blank row between every original row?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 09:38:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74577#M18796</guid>
      <dc:creator>sjlin</dc:creator>
      <dc:date>2013-06-25T09:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup Table Problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74578#M18797</link>
      <description>&lt;P&gt;It means the file name is wrong in the transforms.conf or the file is locked by some other process or splunk doesn't have read access to the location. try these options should resolve the issue.&lt;/P&gt;

&lt;P&gt;And i thought the lookup files should be inside the \etc\apps\app_name\lookups folder, Isn't it?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 10:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74578#M18797</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2013-06-25T10:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup Table Problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74579#M18798</link>
      <description>&lt;P&gt;@linu1988 It looks like this lookup table is private, based on the file location.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 23:21:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74579#M18798</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-06-25T23:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup Table Problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74580#M18799</link>
      <description>&lt;P&gt;The docs say "The CSV files used as lookups must be created with UNIX-style line endings." This may also be your problem; there are utilities which can correct line-ending problems. You might find the &lt;CODE&gt;dos2unix&lt;/CODE&gt; utility helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 23:25:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74580#M18799</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-06-25T23:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup Table Problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74581#M18800</link>
      <description>&lt;P&gt;To linu1988:&lt;BR /&gt;
Yes, but after I delete the lookup in Manager/lookup table, I add the lookup table again, and then the lookup file is inside the folder: \etc\users\admin\MyApp\lookups&lt;/P&gt;

&lt;P&gt;Sorry, How can I know if splunk has read access to the lookup table?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 03:26:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-Table-Problem/m-p/74581#M18800</guid>
      <dc:creator>sjlin</dc:creator>
      <dc:date>2013-06-26T03:26:09Z</dc:date>
    </item>
  </channel>
</rss>

