<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: lookup table problem in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82518#M20945</link>
    <description>&lt;P&gt;You've put the csv file in the wrong location. It shouldn't be in &lt;CODE&gt;etc/apps/search/local/lookups&lt;/CODE&gt;, it should be in a lookups directory directly under the app root, i.e. &lt;CODE&gt;etc/apps/search/lookups&lt;/CODE&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jan 2013 18:49:48 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-01-09T18:49:48Z</dc:date>
    <item>
      <title>lookup table problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82517#M20944</link>
      <description>&lt;P&gt;I have already used lookup table with splunk 4.3 and i have never had problems.&lt;BR /&gt;
With 5.0.1 i have a strange problem.&lt;BR /&gt;
I have this in my ../etc/apps/search/local/props.conf file&lt;/P&gt;

&lt;P&gt;[mycsv]&lt;BR /&gt;
LOOKUP-calendar = calendar month OUTPUTNEW my_month&lt;/P&gt;

&lt;P&gt;and in ../etc/apps/search/local/transforms.conf file&lt;/P&gt;

&lt;P&gt;[calendar]&lt;BR /&gt;
filename = calendar.csv&lt;/P&gt;

&lt;P&gt;where calendar is in ../etc/apps/search/local/lookups&lt;/P&gt;

&lt;P&gt;In manager console i have put lookup definition and lookup file objects to global.&lt;BR /&gt;
At search time i have this error:&lt;BR /&gt;
The lookup table 'calendar' does not exist. It is referenced by configuration 'mycsv'.&lt;/P&gt;

&lt;P&gt;Can you healp me?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 18:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82517#M20944</guid>
      <dc:creator>my_splunk</dc:creator>
      <dc:date>2013-01-09T18:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82518#M20945</link>
      <description>&lt;P&gt;You've put the csv file in the wrong location. It shouldn't be in &lt;CODE&gt;etc/apps/search/local/lookups&lt;/CODE&gt;, it should be in a lookups directory directly under the app root, i.e. &lt;CODE&gt;etc/apps/search/lookups&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 18:49:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82518#M20945</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-09T18:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82519#M20946</link>
      <description>&lt;P&gt;Sorry, i have wrote a wrong thing in my post.&lt;BR /&gt;
I have correctly put csv file in etc/apps/search/lookups&lt;BR /&gt;
So why this error at search time?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 18:54:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82519#M20946</guid>
      <dc:creator>my_splunk</dc:creator>
      <dc:date>2013-01-09T18:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82520#M20947</link>
      <description>&lt;P&gt;I don't know, sorry - your conf looks OK to me.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 19:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82520#M20947</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-09T19:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82521#M20948</link>
      <description>&lt;P&gt;as soon as possible i try this same configuration in 4.3 splunk....&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 19:16:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82521#M20948</guid>
      <dc:creator>my_splunk</dc:creator>
      <dc:date>2013-01-09T19:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82522#M20949</link>
      <description>&lt;P&gt;This is my updating. I have seen that there are many known issues abouk lookup with 5.0.1 version and i think i found another.&lt;BR /&gt;
When i use directly conf file (props, transforms) splunk do not find lookup definition, in fact in manager console lookup definition is empty. If i use web interface for lookup creation (i mean manager-&amp;gt;lookup and then in order lookup file, lookup defition and automatic lookup) there are no problem.&lt;BR /&gt;
I tjink this is a bug, how can i report it?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2013 07:46:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82522#M20949</guid>
      <dc:creator>my_splunk</dc:creator>
      <dc:date>2013-01-10T07:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: lookup table problem</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82523#M20950</link>
      <description>&lt;P&gt;Did you restart Splunk after editing the configuration files?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2013 13:47:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-table-problem/m-p/82523#M20950</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-10T13:47:44Z</dc:date>
    </item>
  </channel>
</rss>

