<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic db lookup not found in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/db-lookup-not-found/m-p/38057#M8622</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I just added a db lookup (via db connect), and when I try to use it via a search, I get a "lookup table does not exist" message. It's there, and when I execute the sql via a dbquery, it returns data.  Is there another required step? &lt;/P&gt;</description>
    <pubDate>Wed, 20 Feb 2013 18:22:14 GMT</pubDate>
    <dc:creator>a212830</dc:creator>
    <dc:date>2013-02-20T18:22:14Z</dc:date>
    <item>
      <title>db lookup not found</title>
      <link>https://community.splunk.com/t5/Splunk-Search/db-lookup-not-found/m-p/38057#M8622</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I just added a db lookup (via db connect), and when I try to use it via a search, I get a "lookup table does not exist" message. It's there, and when I execute the sql via a dbquery, it returns data.  Is there another required step? &lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2013 18:22:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/db-lookup-not-found/m-p/38057#M8622</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2013-02-20T18:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: db lookup not found</title>
      <link>https://community.splunk.com/t5/Splunk-Search/db-lookup-not-found/m-p/38058#M8623</link>
      <description>&lt;P&gt;Not sure if you are using the same user that created the db lookup to make the search. I was able to get the lookup table when I used the same user. However, when I use a user with fewer capabilities, I got the same problem.&lt;/P&gt;

&lt;P&gt;I added the dbx_user role to the user who has to search with this db lookup and it worked. However, it will expose the "External Database" section to that user. I'm still finding ways to avoid this while letting that user use the db lookup.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2014 01:25:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/db-lookup-not-found/m-p/38058#M8623</guid>
      <dc:creator>chanst2</dc:creator>
      <dc:date>2014-06-10T01:25:26Z</dc:date>
    </item>
  </channel>
</rss>

