All Apps and Add-ons

After installing the Cisco Networks App and Add-on for Splunk Enterprise 2.3.0 on Splunk 6.2, why do dashboards now show "he lookup table 'cisco_ios_facility_categories' does not exist."

molinarf
Communicator

Lookup table error: The lookup table 'cisco_ios_facility_categories' does not exist. It is referenced by configuration 'source::udp:514|host::10.32.7.7|cisco:ios'.

I upgraded to TA-Cisco_ios 2.3 and ran into this issue. With the errors that were occurring in lookup tables, I removed the app completely and then reinstalled. Both the TA and Cisco Network Apps are at version 2.3. With the IP address, it could be the switch is sending information that Splunk doesn't know how to deal with. Any ideas? I am in the process of trying to determine what the entry in the eventtypes,conf will be and what the switch is trying to send. If you can provide some insight, it would be appreciated.

0 Karma
1 Solution

mikaelbje
Motivator

Did you do a complete reinstall of TA-cisco_ios on your indexers too? Make sure the versions match on indexer and search head. As you said a complete reinstall (delete directories) and re-add apps is necessary. This has solved the exact issue you are facing for others, including myself at various customer sites.

View solution in original post

0 Karma

molinarf
Communicator

Thank you for your assistance. It is not intuitive that we should do a complete re-install and something to remember in the future. When I removed the directories for the TA-cisco_ios and the Cisco network apps and then re-installed, the issue went away.

0 Karma

mikaelbje
Motivator

Sorry about that. Some files were moved from the app to the add-on and vice versa in an previous version and that's why this happens. There's no local/default concept for the lookup directory so any old lookups are retained even when you upgrade apps.

0 Karma

mikaelbje
Motivator

Did you do a complete reinstall of TA-cisco_ios on your indexers too? Make sure the versions match on indexer and search head. As you said a complete reinstall (delete directories) and re-add apps is necessary. This has solved the exact issue you are facing for others, including myself at various customer sites.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...