All Apps and Add-ons

After upgrade Exchange App and Windows TA, I got “Could not load lookup=LOOKUP-user_account_control_property “ error

lianwan
Explorer

I have a cluster deployment with one search cluster and one indexer cluster. Recently I upgraded MS Exchange App to the search cluster:

  • Upgraded windows_TA from 5.0.1 to 7.0.0
  • Upgraded Exchange TAs from 3.5.1 to 4.0.1
  • Upgraded Exchange App from 3.5.1 to 4.0.1
  • Removed windows infrastructure app 1.5.1

The TAs are also pushed to the indexer cluster. I also have removed the windows_apps.csv lookup under Exchange app as there is a newer copy under windows_TA, which suppressed "Could not load lookup=LOOKUP-app4_for_windows_security" error. I did not change anything else to the App.

However, every indexer reports  “Could not load lookup=LOOKUP-user_account_control_property “ error for any searches. The user_account_control_property lookup come with the Windows_TA and is readable by any user/app by default. Could somebody help? Thanks in advance!

 

 

Tags (1)
0 Karma
1 Solution

lianwan
Explorer

It turned out to be I have */bin/* directory in replication blacklist of distsearch.conf in the search cluster. The user_account_control_property lookup happened to be an external type (a python script under Splunk_windows_TA/bin directory). After removing this entry, the, the error went away.

I also replaced the windows_apps.csv lookup under Exchange app with the one under windows_TA to get rid of the "Could not load lookup=LOOKUP-app4_for_windows_security" error.

View solution in original post

lianwan
Explorer

It turned out to be I have */bin/* directory in replication blacklist of distsearch.conf in the search cluster. The user_account_control_property lookup happened to be an external type (a python script under Splunk_windows_TA/bin directory). After removing this entry, the, the error went away.

I also replaced the windows_apps.csv lookup under Exchange app with the one under windows_TA to get rid of the "Could not load lookup=LOOKUP-app4_for_windows_security" error.

Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...