<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting &amp;quot;The lookup table 'dropdownsLookup' does not exist.&amp;quot; errors after every search? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182010#M52469</link>
    <description>&lt;P&gt;I have a single server SH and Indexer&lt;/P&gt;</description>
    <pubDate>Thu, 01 Oct 2015 18:46:10 GMT</pubDate>
    <dc:creator>schultet</dc:creator>
    <dc:date>2015-10-01T18:46:10Z</dc:date>
    <item>
      <title>Why am I getting "The lookup table 'dropdownsLookup' does not exist." errors after every search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182004#M52463</link>
      <description>&lt;P&gt;Every time I do a search, the search results are successful but I get these prompts atop of my search results, each with an orange triangle icon with an exclamation is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Info.csv being bloated by "lookup" log messages . Will not log additional errors. Refer search.log
The limit has been reached for log messages in info.csv. 1 messages have not been written to info.csv. Please refer search.log for these messages or limits.conf to configure this limit.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration '(?i)source::....zip(.\d+)?'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'ActiveDirectory'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'BoxAppForSplunk_controller-too_small'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'Linux:SELinuxConfig'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'PerformanceMonitor'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'Splunk_TA_aws-RestEndpoints-account-list-too_small'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'WinNetMonMk'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'WinPrintMon'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'WinRegistry'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'WinWinHostMon'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration '__singleline'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration '_json'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'access_combined'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'access_combined_wcookie'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'access_common'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'aix_secure'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'anaconda'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'anaconda_syslog'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'apache_error'.
The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration 'asterisk_cdr'.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I don't remember activating anything from another app. I did download the Splunk App for Unix and Linux, but it's disabled at the moment. That was the only thing I can think of that I changed. How do I get rid of this error? Is there another app that I need to disable?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2015 22:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182004#M52463</guid>
      <dc:creator>appzen</dc:creator>
      <dc:date>2015-01-12T22:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table 'dropdownsLookup' does not exist." errors after every search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182005#M52464</link>
      <description>&lt;P&gt;Are you getting this error in a SH cluster? I've noticed this error myself in my test environment. I'm using a deployer server to push updates to my SHC and have noticed that the dropdowns.csv file gets removed. If I redeploy the apps to the SHC the file returns and the errors go away.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jan 2015 01:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182005#M52464</guid>
      <dc:creator>awilliams_splun</dc:creator>
      <dc:date>2015-01-17T01:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table 'dropdownsLookup' does not exist." errors after every search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182006#M52465</link>
      <description>&lt;P&gt;What do you mean by SH cluster?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2015 20:55:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182006#M52465</guid>
      <dc:creator>appzen</dc:creator>
      <dc:date>2015-01-19T20:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table 'dropdownsLookup' does not exist." errors after every search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182007#M52466</link>
      <description>&lt;P&gt;Search Head, one or more in a cluster.  I am getting this error myself, also after installing the Splunk App for Unix and Linux.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2015 14:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182007#M52466</guid>
      <dc:creator>russellliss</dc:creator>
      <dc:date>2015-01-21T14:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table 'dropdownsLookup' does not exist." errors after every search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182008#M52467</link>
      <description>&lt;P&gt;The Splunk App for Unix also installs "SA-nix" and "Splunk_TA_nix".  Remove these as well, and your error should go away.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:39:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182008#M52467</guid>
      <dc:creator>russellliss</dc:creator>
      <dc:date>2020-09-28T18:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table 'dropdownsLookup' does not exist." errors after every search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182009#M52468</link>
      <description>&lt;P&gt;I too and getting these messages now.   &lt;/P&gt;

&lt;P&gt;•The limit has been reached for log messages in info.csv. 16 messages have not been written to info.csv. Please refer to search.log for these messages or limits.conf to configure this limit.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::*:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::13TH|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::43rd|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::CO|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::HP|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::Hypnos|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::LC|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::ND|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::OC|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::PROTEUS|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::Penia|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::SS|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'MSADGroupType' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::ST|WinEventLog:Security'.&lt;BR /&gt;
•The lookup table 'endpoint_change_object_category_lookup' does not exist. It is referenced by configuration 'WinRegistry'.&lt;BR /&gt;
•The lookup table 'endpoint_change_object_category_lookup' does not exist. It is referenced by configuration 'fs_notification'.&lt;BR /&gt;
•The lookup table 'endpoint_change_status_lookup' does not exist. It is referenced by configuration 'WinRegistry'.&lt;BR /&gt;
•The lookup table 'endpoint_change_status_lookup' does not exist. It is referenced by configuration 'fs_notification'.&lt;BR /&gt;
•The lookup table 'endpoint_change_user_type_lookup' does not exist. It is referenced by configuration 'WinRegistry'.&lt;BR /&gt;
•The lookup table 'endpoint_change_vendor_action_lookup' does not exist. It is referenced by configuration 'WinRegistry'.&lt;BR /&gt;
•The lookup table 'endpoint_change_vendor_action_lookup' does not exist. It is referenced by configuration 'fs_notification'.&lt;BR /&gt;
•The lookup table 'fs_notification_change_type_lookup' does not exist. It is referenced by configuration 'fs_notification'.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:26:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182009#M52468</guid>
      <dc:creator>schultet</dc:creator>
      <dc:date>2020-09-29T07:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting "The lookup table 'dropdownsLookup' does not exist." errors after every search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182010#M52469</link>
      <description>&lt;P&gt;I have a single server SH and Indexer&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 18:46:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-quot-The-lookup-table-dropdownsLookup-does-not/m-p/182010#M52469</guid>
      <dc:creator>schultet</dc:creator>
      <dc:date>2015-10-01T18:46:10Z</dc:date>
    </item>
  </channel>
</rss>

