<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Cloud: Lookups in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Cloud-Lookups/m-p/700109#M237599</link>
    <description>&lt;P&gt;Hi Splunk Experts,&lt;/P&gt;&lt;P&gt;I hope to get a quick hint on my issue. I have a Splunk Cloud setup with two search heads, one of which is dedicated to Enterprise Security. I have different lookups on this search head containing, e.g., all user attributes. I wanted to enhance a specific search using the &lt;EM&gt;lookup&lt;/EM&gt; command as described in the documentation.&lt;/P&gt;&lt;P&gt;Additionally, I can access and view the lookup with the &lt;EM&gt;inputlookup&lt;/EM&gt; command, confirming the file’s existence and proper permissions on the search head.&lt;/P&gt;&lt;P&gt;The search I have trouble with (simplified):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main source_type=some_event_related_to_users
| lookup ldap_users.csv identity as src_user&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, this search instantaneously fails with:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[idx-[...].splunkcloud.com,idx-[...].splunkcloud.com,idx-[...].splunkcloud.com] The lookup table 'ldap_users.csv' does not exist or is not available.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I must confess I am rather new to Splunk and even newer to running a Splunk cluster. So I do not really understand why my indexers are looking for the file in the first place. I assumed that the search head would handle the lookup. In addition, as I am a Splunk Cloud customer, I don’t have access to the indexers anyway.&lt;/P&gt;&lt;P&gt;Can someone give me a pointer on how to achieve such a query in a Splunk Cloud Environment?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Sep 2024 15:38:54 GMT</pubDate>
    <dc:creator>Gravoc</dc:creator>
    <dc:date>2024-09-25T15:38:54Z</dc:date>
    <item>
      <title>Splunk Cloud: Lookups</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Cloud-Lookups/m-p/700109#M237599</link>
      <description>&lt;P&gt;Hi Splunk Experts,&lt;/P&gt;&lt;P&gt;I hope to get a quick hint on my issue. I have a Splunk Cloud setup with two search heads, one of which is dedicated to Enterprise Security. I have different lookups on this search head containing, e.g., all user attributes. I wanted to enhance a specific search using the &lt;EM&gt;lookup&lt;/EM&gt; command as described in the documentation.&lt;/P&gt;&lt;P&gt;Additionally, I can access and view the lookup with the &lt;EM&gt;inputlookup&lt;/EM&gt; command, confirming the file’s existence and proper permissions on the search head.&lt;/P&gt;&lt;P&gt;The search I have trouble with (simplified):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main source_type=some_event_related_to_users
| lookup ldap_users.csv identity as src_user&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, this search instantaneously fails with:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[idx-[...].splunkcloud.com,idx-[...].splunkcloud.com,idx-[...].splunkcloud.com] The lookup table 'ldap_users.csv' does not exist or is not available.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I must confess I am rather new to Splunk and even newer to running a Splunk cluster. So I do not really understand why my indexers are looking for the file in the first place. I assumed that the search head would handle the lookup. In addition, as I am a Splunk Cloud customer, I don’t have access to the indexers anyway.&lt;/P&gt;&lt;P&gt;Can someone give me a pointer on how to achieve such a query in a Splunk Cloud Environment?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 15:38:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Cloud-Lookups/m-p/700109#M237599</guid>
      <dc:creator>Gravoc</dc:creator>
      <dc:date>2024-09-25T15:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud: Lookups</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Cloud-Lookups/m-p/700112#M237601</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/272546"&gt;@Gravoc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;at first check if the lookup name is correct (it's case sensitive).&lt;/P&gt;&lt;P&gt;Then check if you see the lookup using the Splunk Lookup Editor App.&lt;/P&gt;&lt;P&gt;Then check if you have created also the Lookup definition for this lookup.&lt;/P&gt;&lt;P&gt;At least check the grants on lookup and lookup definition.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 15:48:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Cloud-Lookups/m-p/700112#M237601</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-25T15:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud: Lookups</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Cloud-Lookups/m-p/700168#M237630</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;thanks for giving this quick reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked the filename either manually and second time by using the following command:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup ldap_users.csv&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This returns the lookup as expected.&lt;/P&gt;&lt;P&gt;I can see and edit my lookup with the lookup editor app.&lt;/P&gt;&lt;P&gt;I also created an Lookup definition and set the permissions on both the lookup and the lookup definition to global read. I also use the lookup in my Enterprise Security Asset Management - and there it works flawlessly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I managed to just utilize the merged identity lookup that Enterprise Security creates. It is not the solution to the original problem - but solves my usecase.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So for me the solution is to just utlitze another lookup:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main source_type=some_event_related_to_users 
| lookup identity_lookup_expanded identity as src_user&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 07:28:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Cloud-Lookups/m-p/700168#M237630</guid>
      <dc:creator>Gravoc</dc:creator>
      <dc:date>2024-09-26T07:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud: Lookups</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Cloud-Lookups/m-p/700210#M237638</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/272546"&gt;@Gravoc&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;maybe you created the lookup in a different app and didn't add the Global sharing level to the lookup and to the definition.&lt;/P&gt;&lt;P&gt;Instead the ES lookups are shared at Global level, probably for this reason it runs.&lt;/P&gt;&lt;P&gt;Try to share as Global lookup and dedinition.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 12:43:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Cloud-Lookups/m-p/700210#M237638</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-26T12:43:15Z</dc:date>
    </item>
  </channel>
</rss>

