<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookups aren't available until Splunk is restarted in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39820#M9121</link>
    <description>&lt;P&gt;The permissions on the lookup tables currently show all apps, though I haven't created a new lookup table since the last Splunk restart...&lt;/P&gt;</description>
    <pubDate>Sun, 06 Feb 2011 13:22:06 GMT</pubDate>
    <dc:creator>jambajuice</dc:creator>
    <dc:date>2011-02-06T13:22:06Z</dc:date>
    <item>
      <title>Lookups aren't available until Splunk is restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39817#M9118</link>
      <description>&lt;P&gt;I've built an app that uses over twenty lookup tables.  I deleted them all and have been trying to test and document the process of building all of the tables.  After building the first lookup table, I've tried running other saved searches that use that table for a lookup.  The search always says that the lookup table is not available.  &lt;/P&gt;

&lt;P&gt;I see the lookup table in the appname/lookups folder and it contains the right data.  If I restart Splunk, the search completes as expected.  &lt;/P&gt;

&lt;P&gt;Is there any way to make Splunk see a new lookup table without restarting?  &lt;/P&gt;

&lt;P&gt;Thx.&lt;/P&gt;

&lt;P&gt;Craig&lt;/P&gt;</description>
      <pubDate>Sun, 06 Feb 2011 09:19:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39817#M9118</guid>
      <dc:creator>jambajuice</dc:creator>
      <dc:date>2011-02-06T09:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups aren't available until Splunk is restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39818#M9119</link>
      <description>&lt;P&gt;It sounds as if your lookup is being loaded fine without restarting, since you're receiving the error message.  I would bet that this issue is one of context, where you're attempting to use the lookup from an app (i.e. Search app) other than the one where it's defined (i.e. MyCustomLookupApp).  You need to set permissions to use the lookup outside the context of the app in which it is defined.&lt;/P&gt;

&lt;P&gt;It's easiest to understand where the permissions need to be set by walking through a UI-configured lookup.  You can build your lookups through the UI in &lt;STRONG&gt;Manager--&amp;gt;Lookups&lt;/STRONG&gt;.  There is a tutorial here:
&lt;A href="http://www.splunk.com/base/Documentation/4.1.6/User/Fieldlookupstutorial" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.6/User/Fieldlookupstutorial&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Using this method to configure a lookup will alleviate any doubt that you need to restart and help to identify each place where permissions need to be set.  (i.e.  Table File, Definitions, Automatic Lookup).&lt;/P&gt;

&lt;P&gt;HTH&lt;BR /&gt;
ron&lt;/P&gt;</description>
      <pubDate>Sun, 06 Feb 2011 11:37:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39818#M9119</guid>
      <dc:creator>Ron_Naken</dc:creator>
      <dc:date>2011-02-06T11:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups aren't available until Splunk is restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39819#M9120</link>
      <description>&lt;P&gt;The lookup table is in the same app that I'm running the search from.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Feb 2011 13:19:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39819#M9120</guid>
      <dc:creator>jambajuice</dc:creator>
      <dc:date>2011-02-06T13:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups aren't available until Splunk is restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39820#M9121</link>
      <description>&lt;P&gt;The permissions on the lookup tables currently show all apps, though I haven't created a new lookup table since the last Splunk restart...&lt;/P&gt;</description>
      <pubDate>Sun, 06 Feb 2011 13:22:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39820#M9121</guid>
      <dc:creator>jambajuice</dc:creator>
      <dc:date>2011-02-06T13:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups aren't available until Splunk is restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39821#M9122</link>
      <description>&lt;P&gt;I tried this in the lab and noticed that when I add props/transforms to do the lookup, I don't get a UI entry for Definitions, but I get one for Lookup and File -- I receive the same error.  Adding the Definition in the UI fixed the issue, but it didn't make any change to props or tranforms.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2011 07:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39821#M9122</guid>
      <dc:creator>Ron_Naken</dc:creator>
      <dc:date>2011-02-07T07:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups aren't available until Splunk is restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39822#M9123</link>
      <description>&lt;P&gt;Ron, I agree that getting the permissions all setup properly can be an issue, and it's often difficult to find which piece is missing. But I too have seen some situation where it appears that the only "solution" to getting a lookup working properly, is to restart splunkd like jambajuice is asking about.  There does seems to be something glitchy about this, but I haven't taken the time to track it down precisely.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2011 00:18:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-aren-t-available-until-Splunk-is-restarted/m-p/39822#M9123</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2011-02-08T00:18:52Z</dc:date>
    </item>
  </channel>
</rss>

