<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting &amp;quot;The lookup table '...' does not exist.&amp;quot; errors after upgrading from Splunk 6.0.1 to 6.2.1? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132555#M36181</link>
    <description>&lt;P&gt;...make sure those lookup configurations are correct and the lookups actually exist?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Apr 2015 20:47:38 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2015-04-09T20:47:38Z</dc:date>
    <item>
      <title>Why am I getting "The lookup table '...' does not exist." errors after upgrading from Splunk 6.0.1 to 6.2.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132554#M36180</link>
      <description>&lt;P&gt;These are the errors I am getting:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;The lookup table 'endpoint_change_object_category_lookup' does not exist. It is referenced by configuration 'WinRegistry'.
 The lookup table 'endpoint_change_object_category_lookup' does not exist. It is referenced by configuration 'fs_notification'.
 The lookup table 'endpoint_change_status_lookup' does not exist. It is referenced by configuration 'WinRegistry'.
 The lookup table 'endpoint_change_status_lookup' does not exist. It is referenced by configuration 'fs_notification'.
 The lookup table 'endpoint_change_user_type_lookup' does not exist. It is referenced by configuration 'WinRegistry'.
 The lookup table 'endpoint_change_vendor_action_lookup' does not exist. It is referenced by configuration 'WinRegistry'.
 The lookup table 'endpoint_change_vendor_action_lookup' does not exist. It is referenced by configuration 'fs_notification'.
 The lookup table 'fs_notification_change_type_lookup' does not exist. It is referenced by configuration 'fs_notification'.
 The lookup table 'msdhcp_signature_lookup' does not exist. It is referenced by configuration 'DhcpSrvLog'.
 The lookup table 'windows_event_descriptions' does not exist. It is referenced by configuration 'source::(MonitorWare|NTSyslog|Snare|WinEventLog|WMI:WinEventLog)...'.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 09 Apr 2015 20:39:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132554#M36180</guid>
      <dc:creator>LVogeding</dc:creator>
      <dc:date>2015-04-09T20:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table '...' does not exist." errors after upgrading from Splunk 6.0.1 to 6.2.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132555#M36181</link>
      <description>&lt;P&gt;...make sure those lookup configurations are correct and the lookups actually exist?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 20:47:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132555#M36181</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-04-09T20:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table '...' does not exist." errors after upgrading from Splunk 6.0.1 to 6.2.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132556#M36182</link>
      <description>&lt;P&gt;Thank you for the quick answer....I am new to splunk. What we had worked in 6.0.1 and not 6.2.1. Where would I start looking at?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 20:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132556#M36182</guid>
      <dc:creator>LVogeding</dc:creator>
      <dc:date>2015-04-09T20:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table '...' does not exist." errors after upgrading from Splunk 6.0.1 to 6.2.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132557#M36183</link>
      <description>&lt;P&gt;Some of those lookups sound as if they come from the Splunk *nix app (&lt;A href="https://splunkbase.splunk.com/app/273/"&gt;https://splunkbase.splunk.com/app/273/&lt;/A&gt;), so check in &lt;CODE&gt;.../etc/apps/Splunk_TA_nix/lookups&lt;/CODE&gt; that they exist and that your splunk user has correct permissions.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2015 21:15:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132557#M36183</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-04-09T21:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table '...' does not exist." errors after upgrading from Splunk 6.0.1 to 6.2.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132558#M36184</link>
      <description>&lt;P&gt;I have the same problem. Search head and index cluster, both have the appropriate bits installed (App, SA, and/or TA - SA and TA from the app/install directory) as specified by the instructions but I get this error from every index cluster member on every search. It seems like I didn't start seeing this error until upgrading from 6.3.0 to 6.3.1 on clustered hosts.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2015 19:24:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132558#M36184</guid>
      <dc:creator>cudgel</dc:creator>
      <dc:date>2015-12-15T19:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table '...' does not exist." errors after upgrading from Splunk 6.0.1 to 6.2.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132559#M36185</link>
      <description>&lt;P&gt;Check the owner &amp;amp; permissions of the lookups and the user splund process is running as.  .../etc/apps/Splunk_TA_nix/lookups &lt;/P&gt;

&lt;P&gt;You might want to recursively chown all your splunk directories&lt;/P&gt;

&lt;P&gt;chown -Rf splunkUser:splunkGroup ....&lt;/P&gt;

&lt;P&gt;My guess is someone ran splunkd as root when upgrading and root took ownership of several files, etc.  Or something similar.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:07:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132559#M36185</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-29T08:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table '...' does not exist." errors after upgrading from Splunk 6.0.1 to 6.2.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132560#M36186</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I faced the same issue as well after I upgraded to 6.2.1, and I found the difference between old version and the new one is the reference to csv lookup file in props.conf.&lt;/P&gt;

&lt;P&gt;In 6.0.1 props.conf &lt;BR /&gt;
[sourcetype]&lt;BR /&gt;
LOOKUP-test_lookup = &lt;STRONG&gt;test_lookup_file&lt;/STRONG&gt; field_1 OUTPUT new_field&lt;/P&gt;

&lt;P&gt;In 6.2.1 props.conf&lt;BR /&gt;
[sourcetype]&lt;BR /&gt;
LOOKUP-test_lookup = &lt;STRONG&gt;test_lookup_file.csv&lt;/STRONG&gt; field_1 OUTPUT new_field&lt;/P&gt;

&lt;P&gt;The difference is that the extension of lookup file should be added.&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:29:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132560#M36186</guid>
      <dc:creator>aakwah</dc:creator>
      <dc:date>2020-09-29T10:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table '...' does not exist." errors after upgrading from Splunk 6.0.1 to 6.2.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132561#M36187</link>
      <description>&lt;P&gt;Adding the extension changes the meaning - with .csv, you're referring to a lookup file stored in some /lookups directory; without .csv, you're referring to a lookup definition stored in transforms.conf.&lt;/P&gt;

&lt;P&gt;If adding .csv fixes things for you, it really means your lookup definition is broken, not shared correctly, not named properly, etc.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 17:04:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132561#M36187</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-08-05T17:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table '...' does not exist." errors after upgrading from Splunk 6.0.1 to 6.2.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132562#M36188</link>
      <description>&lt;P&gt;Thanks Martin for the heads up, yes I forgot to define my lookups in the transforms.conf in my new installation.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 07:50:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132562#M36188</guid>
      <dc:creator>aakwah</dc:creator>
      <dc:date>2016-08-08T07:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table '...' does not exist." errors after upgrading from Splunk 6.0.1 to 6.2.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132563#M36189</link>
      <description>&lt;P&gt;The best way I found is to go to the /etc/apps directory and run:&lt;/P&gt;

&lt;P&gt;grep -r "lookup-file-causing-error" *&lt;/P&gt;

&lt;P&gt;This will find all instances. You can then disable or uninstall whichever app is associated to confirm the error messages go away. That at least allows you to focus on which lookup is broken.&lt;/P&gt;

&lt;P&gt;In my case, it was due to uninstalling the TA_SalesForce, but the Splunk App for Salesforce was still installed.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 13:31:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-does-not-exist-quot/m-p/132563#M36189</guid>
      <dc:creator>gordo32</dc:creator>
      <dc:date>2018-06-26T13:31:10Z</dc:date>
    </item>
  </channel>
</rss>

