<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Lookup table errors after 6.0 upgrade in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-errors-after-6-0-upgrade/m-p/121983#M32830</link>
    <description>&lt;P&gt;Hi, after upgrading our search head from 4.3 to 6.0, we are getting error messages when doing custom searches.&lt;BR /&gt;
The errors are reported from all the search peers (ex: awssplunkindex.yp1.ca). The search peers are enabled and replication is successful. The search peers are version 5.0 or 4.3.&lt;/P&gt;

&lt;P&gt;[awssplunkindex.yp1.ca] The lookup table 'http_status_lookup' does not exist. It is referenced by configuration 'apache'.&lt;BR /&gt;
[awssplunkindex.yp1.ca] The lookup table 'logMapping_mobile' does not exist. It is referenced by configuration '24hrPC-cgi'.&lt;BR /&gt;
[awssplunkindex.yp1.ca] The lookup table 'logMapping_mobile' does not exist. It is referenced by configuration '24hrPC-telus'. &lt;/P&gt;

&lt;P&gt;I tried disabling/enabling the search peers and restarting them, without success.&lt;/P&gt;

&lt;P&gt;Thank you for your help&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 15:08:31 GMT</pubDate>
    <dc:creator>vathanal</dc:creator>
    <dc:date>2020-09-28T15:08:31Z</dc:date>
    <item>
      <title>Lookup table errors after 6.0 upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-errors-after-6-0-upgrade/m-p/121983#M32830</link>
      <description>&lt;P&gt;Hi, after upgrading our search head from 4.3 to 6.0, we are getting error messages when doing custom searches.&lt;BR /&gt;
The errors are reported from all the search peers (ex: awssplunkindex.yp1.ca). The search peers are enabled and replication is successful. The search peers are version 5.0 or 4.3.&lt;/P&gt;

&lt;P&gt;[awssplunkindex.yp1.ca] The lookup table 'http_status_lookup' does not exist. It is referenced by configuration 'apache'.&lt;BR /&gt;
[awssplunkindex.yp1.ca] The lookup table 'logMapping_mobile' does not exist. It is referenced by configuration '24hrPC-cgi'.&lt;BR /&gt;
[awssplunkindex.yp1.ca] The lookup table 'logMapping_mobile' does not exist. It is referenced by configuration '24hrPC-telus'. &lt;/P&gt;

&lt;P&gt;I tried disabling/enabling the search peers and restarting them, without success.&lt;/P&gt;

&lt;P&gt;Thank you for your help&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:08:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-errors-after-6-0-upgrade/m-p/121983#M32830</guid>
      <dc:creator>vathanal</dc:creator>
      <dc:date>2020-09-28T15:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup table errors after 6.0 upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-errors-after-6-0-upgrade/m-p/121984#M32831</link>
      <description>&lt;P&gt;I am having the same issue. I suspect you followed the advice on &lt;A href="http://answers.splunk.com/answers/35267/very-large-lookup-tables-exceeding-2gb-bundle-size"&gt;http://answers.splunk.com/answers/35267/very-large-lookup-tables-exceeding-2gb-bundle-size&lt;/A&gt;&lt;BR /&gt;
which removes the lookups from your replication bundle. This is the desired behavior, but then automatic lookups fail. I am trying to find out how to enable automatic lookups only on Search Heads and not get the search error messages.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2014 17:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-errors-after-6-0-upgrade/m-p/121984#M32831</guid>
      <dc:creator>bmas10</dc:creator>
      <dc:date>2014-03-18T17:36:16Z</dc:date>
    </item>
  </channel>
</rss>

