<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup upload Error in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34328#M7359</link>
    <description>&lt;P&gt;Can the admin copy the file into the appropriate lookups directory from the command line (Linux, Windows, whatever)?&lt;/P&gt;</description>
    <pubDate>Wed, 14 Nov 2012 18:17:32 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2012-11-14T18:17:32Z</dc:date>
    <item>
      <title>Lookup upload Error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34327#M7358</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have an alert set up to compare hosts with my look-up table .csv file. It was working fine in Splunk 4.3.3 build 128297.&lt;BR /&gt;
We recently did a failover to Splunk 4.2.1(98164) and I'm not able to recreate this.&lt;/P&gt;

&lt;P&gt;This file just won't upload. It gives the following error:&lt;/P&gt;

&lt;P&gt;Encountered the following error while trying to save: In handler 'lookup-table-files': Error performing action=create on object id=testfile.csv in config=lookups.&lt;/P&gt;

&lt;P&gt;I am a privileged user. I did this without a problem earlier. I asked my admin to upload it, he received the same error. What could be the issue?&lt;/P&gt;

&lt;P&gt;edit: Found a difference in where splunk saves the files. (Assume my username as aniketb)&lt;/P&gt;

&lt;P&gt;Splunk 4.3.3 saved the lookup to: /opt/splunk/etc/apps/search/lookups/testfile.csv &lt;BR /&gt;
Splunk 4.2.1 saved to: /opt/splunk/etc/users/aniketb/search/lookups/testfile.csv&lt;/P&gt;

&lt;P&gt;Does this point to any error?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2012 16:34:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34327#M7358</guid>
      <dc:creator>aniketb</dc:creator>
      <dc:date>2012-11-14T16:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup upload Error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34328#M7359</link>
      <description>&lt;P&gt;Can the admin copy the file into the appropriate lookups directory from the command line (Linux, Windows, whatever)?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2012 18:17:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34328#M7359</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-11-14T18:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup upload Error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34329#M7360</link>
      <description>&lt;P&gt;Maybe yes but that would be a one time workaround. The host list keeps updating, you can't go to admin every time to upload the lookup. We tried with setting all permissions ON, still got the same error. &lt;BR /&gt;
Any possible hints to configuration problems?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2012 18:32:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34329#M7360</guid>
      <dc:creator>aniketb</dc:creator>
      <dc:date>2012-11-14T18:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup upload Error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34330#M7361</link>
      <description>&lt;P&gt;What is it that keeps updating the host list?  For instance is it a scheduled search that uses the outputlookup command, or is it a script that just writes a new file to disk?   I'm wondering if it's some difference around file permissions in lookup handling, between 4.3 and 4.2.X.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2012 18:36:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34330#M7361</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2012-11-14T18:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup upload Error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34331#M7362</link>
      <description>&lt;P&gt;The scheduled search uses inputlookup. &lt;BR /&gt;
I'm using this from security point to monitor access by  trusted hosts. Since this is a learning phase, after the alerts are flagged, we review if we have to add the flagged ones to the trusted list.&lt;/P&gt;

&lt;P&gt;Related to: &lt;A href="http://splunk-base.splunk.com/answers/54370/updating-a-lookup-table-by-external-means"&gt;http://splunk-base.splunk.com/answers/54370/updating-a-lookup-table-by-external-means&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2012 18:43:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34331#M7362</guid>
      <dc:creator>aniketb</dc:creator>
      <dc:date>2012-11-14T18:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup upload Error</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34332#M7363</link>
      <description>&lt;P&gt;This issue happened with me when I've a column that has German letters ü,ß,ä ... &lt;BR /&gt;
after I removed this column from csv file it uploaded successfully &lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2015 16:45:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-upload-Error/m-p/34332#M7363</guid>
      <dc:creator>aakwah</dc:creator>
      <dc:date>2015-01-14T16:45:05Z</dc:date>
    </item>
  </channel>
</rss>

