<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup csv in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33862#M7223</link>
    <description>&lt;P&gt;Is that the exact error? It looks similar to a current splunk bug on 4.3.3 which occurs when you have a sub search in your search string. Csvs can contain many many more records than 300k so it could be the aforementioned bug you are hitting instead.&lt;/P&gt;

&lt;P&gt;Update:&lt;/P&gt;

&lt;P&gt;Subsearch failing with the error "Encountered an error while reading file '/opt/splunk/var/run/splunk/dispatchtmp/subsearch_&lt;EM&gt;/prereport_&lt;/EM&gt;.csv.gz'.", the workaround is to format the fields with the command fields instead of table at the end of the sub search. (SPL-52862)&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:15:36 GMT</pubDate>
    <dc:creator>Drainy</dc:creator>
    <dc:date>2020-09-28T12:15:36Z</dc:date>
    <item>
      <title>Lookup csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33861#M7222</link>
      <description>&lt;P&gt;May I know if there is any size limit of the csv file when performing a lookup?&lt;/P&gt;

&lt;P&gt;I'm doing a lookup to a csv with around 300k records, encounter the error below.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Encountered an error while reading file 'D:\Splunk\var\run\splunk\dispatchtmp\subsearch_admin__admin__search&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:15:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33861#M7222</guid>
      <dc:creator>wj</dc:creator>
      <dc:date>2020-09-28T12:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33862#M7223</link>
      <description>&lt;P&gt;Is that the exact error? It looks similar to a current splunk bug on 4.3.3 which occurs when you have a sub search in your search string. Csvs can contain many many more records than 300k so it could be the aforementioned bug you are hitting instead.&lt;/P&gt;

&lt;P&gt;Update:&lt;/P&gt;

&lt;P&gt;Subsearch failing with the error "Encountered an error while reading file '/opt/splunk/var/run/splunk/dispatchtmp/subsearch_&lt;EM&gt;/prereport_&lt;/EM&gt;.csv.gz'.", the workaround is to format the fields with the command fields instead of table at the end of the sub search. (SPL-52862)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:15:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33862#M7223</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2020-09-28T12:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33863#M7224</link>
      <description>&lt;P&gt;Hi Drainy, &lt;/P&gt;

&lt;P&gt;The full error message. &lt;/P&gt;

&lt;P&gt;Encountered an error while reading file 'D:\Splunk\var\run\splunk\dispatchtmp\subsearch_admin_&lt;EM&gt;admin&lt;/EM&gt;_search_TWFsaWNpb3VzIElQIHNlYXJjaCBieSBkc3Q_1344931019.717_1344931019.1\collapse-132809093_0.csv.gz'.&lt;/P&gt;

&lt;P&gt;I was able to perform the same search with a smaller csv file though. &lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:15:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33863#M7224</guid>
      <dc:creator>wj</dc:creator>
      <dc:date>2020-09-28T12:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33864#M7225</link>
      <description>&lt;P&gt;Yeah this sounds like the bug. No subsearch included? Also it may pop up somewhere else. Bear in mind that CSV at the end of that is unrelated to the fact that you may be using a CSV in your search. I've updated my answer with the bug detail. I believe a fix is due in the next maintenance release.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2012 08:18:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33864#M7225</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-08-14T08:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33865#M7226</link>
      <description>&lt;P&gt;Upgrading Splunk to 4.3.4 should fix the issue&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2012 22:33:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv/m-p/33865#M7226</guid>
      <dc:creator>MillerTime</dc:creator>
      <dc:date>2012-09-19T22:33:06Z</dc:date>
    </item>
  </channel>
</rss>

