All Apps and Add-ons
Highlighted

Could not load lookup=LOOKUP-user_account_control_property

Communicator

After updating SplunkTAWindows to version 6.0.0, I am getting error messages on every search I run.

[INDEXER 1] Could not load lookup=LOOKUP-useraccountcontrolproperty
[INDEXER 2] Could not load lookup=LOOKUP-user
accountcontrolproperty
[INDEXER 3] Could not load lookup=LOOKUP-useraccountcontrolproperty
[HEAVY FORWARDER] Could not load lookup=LOOKUP-user
accountcontrolproperty

All my instances (SH, Indexers and HF) are using the same version of SplunkTAWindows (6.0.0) and Splunk Enterprise (7.2.6). I am able to find this lookup in the SplunkTAWindows folder, using CLI, but It looks like Splunk is not finding It in any of my instances. When I disable this lookup in my SH I still get error messages.

Any tips on how to solve this issue? Does anyone knows what causes this error messages?

Highlighted

Re: Could not load lookup=LOOKUP-user_account_control_property

SplunkTrust
SplunkTrust

Have you looked at the transforms.conf related to those lookup definitions and also permissions (in default.meta/local.meta) or Via GUI? if they are available, they got to have export=system permissions.

0 Karma
Highlighted

Re: Could not load lookup=LOOKUP-user_account_control_property

Communicator

Hi

In my default/transforms.conf I have this:

[useraccountcontrolproperty]
external
cmd = useraccountcontrolproperty.py userAccountControl userAccountPropertyFlag
external
type = python
fields_list = userAccountControl,userAccountPropertyFlag

And the python script is located ate splunktawindows/bin.

0 Karma