<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help on could not load lookup message in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/help-on-could-not-load-lookup-message/m-p/659724#M227767</link>
    <description>&lt;P&gt;This probably means that they are defined as automatic lookups, so will always be executed if the matching conditions are true for that lookup definition, e.g. it is the correct sourcetype.&lt;/P&gt;&lt;P&gt;The fact that it is failing could be that you don't have permissions to see some part of the lookup or that the lookup is not present and the definition is trying to refer to a non existent lookup, or that the automatic lookup definition is wrong. For example you can cause this problem by creating a field in the automatic lookup that does not exist in the lookup file and you will get this message.&lt;/P&gt;&lt;P&gt;Do you have a Splunk sys admin - they should look at this to find out what is wrong with the automatic lookup.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2023 21:25:23 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2023-10-04T21:25:23Z</dc:date>
    <item>
      <title>help on could not load lookup message</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-could-not-load-lookup-message/m-p/659607#M227735</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;When I run a search i have the message "could not load lookup" with different lookup name&lt;/P&gt;&lt;P&gt;For example :&lt;/P&gt;&lt;P&gt;Could not load lookup=LOOKUP-Kerberosfailurecode&lt;/P&gt;&lt;P&gt;Could not load lookup=LOOKUP-Kerberosresultcode&lt;/P&gt;&lt;P&gt;Could not load lookup=LOOKUP-syscall&lt;/P&gt;&lt;P&gt;I had a look in the lookup definition menu and I can see that some lookup are referenced to my splunk apps even if i dont use these lookups in my apps!&lt;/P&gt;&lt;P&gt;But i can change the name of the apps&lt;/P&gt;&lt;P&gt;Is it possible to change it?&lt;/P&gt;&lt;P&gt;Moreover, some lookup like "syscall" doesnt exists in my lookup definition menu&lt;/P&gt;&lt;P&gt;so how to solve this issue please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 08:04:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-could-not-load-lookup-message/m-p/659607#M227735</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2023-10-04T08:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: help on could not load lookup message</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-could-not-load-lookup-message/m-p/659724#M227767</link>
      <description>&lt;P&gt;This probably means that they are defined as automatic lookups, so will always be executed if the matching conditions are true for that lookup definition, e.g. it is the correct sourcetype.&lt;/P&gt;&lt;P&gt;The fact that it is failing could be that you don't have permissions to see some part of the lookup or that the lookup is not present and the definition is trying to refer to a non existent lookup, or that the automatic lookup definition is wrong. For example you can cause this problem by creating a field in the automatic lookup that does not exist in the lookup file and you will get this message.&lt;/P&gt;&lt;P&gt;Do you have a Splunk sys admin - they should look at this to find out what is wrong with the automatic lookup.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 21:25:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-could-not-load-lookup-message/m-p/659724#M227767</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-10-04T21:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: help on could not load lookup message</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-on-could-not-load-lookup-message/m-p/659906#M227825</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;No sys admin unfortunately&lt;/P&gt;&lt;P&gt;So im going to try to correct it...&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 05:13:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-on-could-not-load-lookup-message/m-p/659906#M227825</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2023-10-06T05:13:33Z</dc:date>
    </item>
  </channel>
</rss>

