<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Receiving error: Could not load lookup=LOOKUP-splunk_security_essentials in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/671422#M230101</link>
    <description>&lt;P&gt;Hi, I’m new to splunk and getting the same error message after upgrading splunk and the security essentials apps.&amp;nbsp;&lt;BR /&gt;could you please help me understand how I can perform these steps:&lt;/P&gt;&lt;P&gt;First and foremost,&lt;/P&gt;&lt;P&gt;- you need to track down the automatic lookup definition&lt;/P&gt;&lt;P&gt;- record the lookup definition name being referenced&lt;/P&gt;&lt;P&gt;- find the lookup definition and record the lookup table name&lt;/P&gt;</description>
    <pubDate>Mon, 11 Dec 2023 08:45:39 GMT</pubDate>
    <dc:creator>Orange_girl</dc:creator>
    <dc:date>2023-12-11T08:45:39Z</dc:date>
    <item>
      <title>Receiving error: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/547906#M155371</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wanted to update&amp;nbsp;&lt;SPAN&gt;splunk_security_essentials app (3.2.2 to 3.3.2) : after I did the restart, I have this error under all searches :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"Could not load lookup=LOOKUP-splunk_security_essentials"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I found out that there is an automatic lookup set like that :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mah_0-1618408146734.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13764iE9577109DA03B19F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mah_0-1618408146734.png" alt="mah_0-1618408146734.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mah_2-1618408199958.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13766iF4786CFCA1D14EF5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mah_2-1618408199958.png" alt="mah_2-1618408199958.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I did a btool command and see this :&lt;/P&gt;
&lt;P&gt;opt/splunk/bin/splunk btool props list --debug |grep LOOKUP-splunk_security_essentials&lt;/P&gt;
&lt;P&gt;/opt/splunk/etc/apps/Splunk_Security_Essentials/default/props.conf LOOKUP-splunk_security_essentials = sse_content_exported_lookup search_title AS search_name OUTPUTNEW&lt;/P&gt;
&lt;P&gt;What can I&amp;nbsp; do to remove this error ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 13:48:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/547906#M155371</guid>
      <dc:creator>mah</dc:creator>
      <dc:date>2023-06-12T13:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/574339#M200154</link>
      <description>&lt;P&gt;I am also encountering this error on 3.4.0. Have you found a solution? Considering trying a rollback.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 08:01:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/574339#M200154</guid>
      <dc:creator>aaron_barrett</dc:creator>
      <dc:date>2021-11-10T08:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/583278#M203094</link>
      <description>&lt;P&gt;Did you manage to solve this?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 20:53:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/583278#M203094</guid>
      <dc:creator>davvik</dc:creator>
      <dc:date>2022-02-01T20:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/623004#M216591</link>
      <description>&lt;P&gt;Same issue &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 10:25:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/623004#M216591</guid>
      <dc:creator>tro</dc:creator>
      <dc:date>2022-12-02T10:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/646592#M223807</link>
      <description>&lt;P&gt;Hi there!&lt;/P&gt;&lt;P&gt;I had same issue after upgrading from version 9.0.4.1 to 9.0.5.&lt;/P&gt;&lt;P&gt;The upgrade process had been started by root user and I had Permission issues with different files.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my experience running the below command resolved the issue.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;# chown -R splunk:splunk /opt/splunk&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 09:07:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/646592#M223807</guid>
      <dc:creator>esafaei</dc:creator>
      <dc:date>2023-06-12T09:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving error: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/647565#M224132</link>
      <description>&lt;P&gt;Hello, this issue has been seen in test environment not in production so we removed it from test environment without resolution.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 09:34:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/647565#M224132</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-06-20T09:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/647566#M224133</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;this didn't help, hopefully this only happened in test env.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 09:34:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/647566#M224133</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-06-20T09:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving error: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/651026#M225089</link>
      <description>&lt;P&gt;We recently encounter a similar error on some searches and we found out that the source of the problem was the KVStore failing to initialize because expired certificates.&lt;BR /&gt;&lt;BR /&gt;After renewing the web certificates the error no longer shows up.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 15:40:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/651026#M225089</guid>
      <dc:creator>joshiro</dc:creator>
      <dc:date>2023-07-18T15:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving error: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/667952#M229170</link>
      <description>&lt;P&gt;Are you still having this issue with the latest SSE app v3.7.1?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 18:20:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/667952#M229170</guid>
      <dc:creator>m_pham</dc:creator>
      <dc:date>2023-11-08T18:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving error: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/669217#M229537</link>
      <description>&lt;P&gt;I just did a clean install of 9.1.1 and then Splunk Security Essentials 3.7.1 and am getting this error.&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228716"&gt;@m_pham&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:10:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/669217#M229537</guid>
      <dc:creator>JusAnotherAdmin</dc:creator>
      <dc:date>2023-11-20T16:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving error: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/669227#M229541</link>
      <description>&lt;P&gt;There can be various reasons for this issue but here are the common ways to troubleshoot this error.&lt;/P&gt;&lt;P&gt;First and foremost,&lt;/P&gt;&lt;P&gt;- you need to track down the automatic lookup definition&lt;/P&gt;&lt;P&gt;- record the lookup definition name being referenced&lt;/P&gt;&lt;P&gt;- find the lookup definition and record the lookup table name and then go check the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;&lt;P&gt;Check if your lookup file exist - you can use the Lookup Editor app to check this or go to: &lt;FONT face="courier new,courier"&gt;Settings &amp;gt; Lookups &amp;gt; Lookup table files&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Check if your lookup definition exist - you can check this by going to &lt;FONT face="courier new,courier"&gt;Settings &amp;gt; Lookups &amp;gt; Lookup definition&lt;/FONT&gt; If you are using an automatic lookup check the following:&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;&lt;P&gt;Do you have the correct read &lt;A class="" title="https://docs.splunk.com/Documentation/SplunkCloud/latest/Knowledge/Usefieldlookupstoaddinformationtoyourevents#Share_a_lookup_table_file_with_apps" href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Knowledge/Usefieldlookupstoaddinformationtoyourevents#Share_a_lookup_table_file_with_apps" target="_blank" rel="noopener"&gt;permission&lt;/A&gt; to the lookup &lt;STRONG&gt;definition&lt;/STRONG&gt; and lookup &lt;STRONG&gt;table&lt;/STRONG&gt;?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If the permissions are correct, check the lookup table size (see step #3)&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If you are using the lookup command:&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;&lt;P&gt;Do you have &lt;A class="" title="https://docs.splunk.com/Documentation/SplunkCloud/latest/Knowledge/Usefieldlookupstoaddinformationtoyourevents#Share_a_lookup_table_file_with_apps" href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Knowledge/Usefieldlookupstoaddinformationtoyourevents#Share_a_lookup_table_file_with_apps" target="_blank" rel="noopener"&gt;permission&lt;/A&gt; to the lookup table or lookup definition?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Does your lookup &lt;A class="" title="https://docs.splunk.com/Documentation/SplunkCloud/latest/Knowledge/Usefieldlookupstoaddinformationtoyourevents#Create_a_CSV_lookup_definition" href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Knowledge/Usefieldlookupstoaddinformationtoyourevents#Create_a_CSV_lookup_definition" target="_blank" rel="noopener"&gt;definition&lt;/A&gt; exist?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Does your search runs fine with adding local=true to your lookup command? This means that your lookup isn't being replicated to the indexer cluster, see step #4.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Rare that this happens, but check the lookup table size for the lookup listed in the automatic lookup and check if it exceeds the size defined in &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;[replicationSettings]&lt;/FONT&gt;&amp;nbsp;&lt;/STRONG&gt;in &lt;FONT face="courier new,courier"&gt;distsearch.conf&lt;/FONT&gt;. If the lookup table exceeds whatever size is defined there, the lookup error comes up.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Check if the lookup being used is in the deny list under distsearch.conf&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;btool distsearch list replicationBlacklist --debug&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;btool distsearch list replicationDenylist--debug&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;Update:&lt;BR /&gt;&lt;/STRONG&gt;- I installed SSE app v3.7.1 on a new Nix host with Splunk v9.1.1 and I didn't see any lookup errors when I run a search. So I recommend you follow the troubleshooting steps above since I can't replicate the issue with a fresh app and Splunk install.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 19:03:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/669227#M229541</guid>
      <dc:creator>m_pham</dc:creator>
      <dc:date>2023-11-20T19:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving error: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/671422#M230101</link>
      <description>&lt;P&gt;Hi, I’m new to splunk and getting the same error message after upgrading splunk and the security essentials apps.&amp;nbsp;&lt;BR /&gt;could you please help me understand how I can perform these steps:&lt;/P&gt;&lt;P&gt;First and foremost,&lt;/P&gt;&lt;P&gt;- you need to track down the automatic lookup definition&lt;/P&gt;&lt;P&gt;- record the lookup definition name being referenced&lt;/P&gt;&lt;P&gt;- find the lookup definition and record the lookup table name&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 08:45:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/671422#M230101</guid>
      <dc:creator>Orange_girl</dc:creator>
      <dc:date>2023-12-11T08:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving error: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/671608#M230136</link>
      <description>&lt;P&gt;Hi - the numbered list provided step by step instructions on searching for the items I mentioned. In addition, the lookup errors you see in the UI usually tells you the name of the lookup related configuration that's having problems.&lt;BR /&gt;&lt;BR /&gt;This doc page should help:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/Knowledge/Aboutlookupsandfieldactions#Lookup_definitions" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.2/Knowledge/Aboutlookupsandfieldactions#Lookup_definitions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 16:18:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/671608#M230136</guid>
      <dc:creator>m_pham</dc:creator>
      <dc:date>2023-12-12T16:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/677209#M231565</link>
      <description>&lt;P&gt;New Windows install and getting this error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wish there was a simple fix as its polluting our POC for a large purchase to get away from other product(s).&lt;/P&gt;</description>
      <pubDate>Sat, 10 Feb 2024 16:27:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/677209#M231565</guid>
      <dc:creator>ChocolateRocket</dc:creator>
      <dc:date>2024-02-10T16:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving error: Could not load lookup=LOOKUP-splunk_security_essentials</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/677213#M231566</link>
      <description>&lt;P&gt;i renamed and replaced the directory with fresh download.&lt;/P&gt;&lt;P&gt;Error has gone away but wondering if I broke a Security app that may have altered the files.&lt;/P&gt;&lt;P&gt;Splunk is so massively large that its daunting for Newbs. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Glad I seemed to have gotten rid of the error though.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Feb 2024 18:04:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Receiving-error-Could-not-load-lookup-LOOKUP-splunk-security/m-p/677213#M231566</guid>
      <dc:creator>ChocolateRocket</dc:creator>
      <dc:date>2024-02-10T18:04:48Z</dc:date>
    </item>
  </channel>
</rss>

