Lookup table error: The lookup table 'cisco_ios_facility_categories' does not exist. It is referenced by configuration 'source::udp:514|host::10.32.7.7|cisco:ios'.
I upgraded to TA-Cisco_ios 2.3 and ran into this issue. With the errors that were occurring in lookup tables, I removed the app completely and then reinstalled. Both the TA and Cisco Network Apps are at version 2.3. With the IP address, it could be the switch is sending information that Splunk doesn't know how to deal with. Any ideas? I am in the process of trying to determine what the entry in the eventtypes,conf will be and what the switch is trying to send. If you can provide some insight, it would be appreciated.
 
					
				
		
Did you do a complete reinstall of TA-cisco_ios on your indexers too? Make sure the versions match on indexer and search head. As you said a complete reinstall (delete directories) and re-add apps is necessary. This has solved the exact issue you are facing for others, including myself at various customer sites.
Thank you for your assistance. It is not intuitive that we should do a complete re-install and something to remember in the future. When I removed the directories for the TA-cisco_ios and the Cisco network apps and then re-installed, the issue went away.
 
					
				
		
Sorry about that. Some files were moved from the app to the add-on and vice versa in an previous version and that's why this happens. There's no local/default concept for the lookup directory so any old lookups are retained even when you upgrade apps.
 
					
				
		
Did you do a complete reinstall of TA-cisco_ios on your indexers too? Make sure the versions match on indexer and search head. As you said a complete reinstall (delete directories) and re-add apps is necessary. This has solved the exact issue you are facing for others, including myself at various customer sites.
