All Apps and Add-ons

Lookup File Editor Not Listing Any CSV Files

bschaap
Path Finder

I installed Lookup Editor (version 3.02) in my Splunk Cloud (version 7.0.3.2) environment. However, none of my existing csv files are listed in Lookup Editor (nor newly added csv's). There are KV Store lookups listed. I have reviewed the FAQ for Lookup Editor without any luck. There is nothing listed in _internal that I can find. The Health / Logs screen shows "No Results Found." in each of the panels. The Health / Status screen displays "Online" for the top two panels. However, it this error message is displayed.

[subsearch]: [idx-x-xxxxxxxxxxxxxxx.xxxxx.splunkcloud.com] REST Processor: Failed to fetch REST endpoint uri=https://127.0.0.1:8089/services/data/lookup_edit/ping?count=0 from server https://127.0.0.1:8089. Check that the URI path provided exists in the REST API.

The bottom two panels on the Health / Status screen shows "No Results Found."

Can anyone suggest any troubleshooting steps or know what the problem is?

0 Karma

LukeMurphey
Champion

This is due to a bug which has been fixed in version 3.0.3. Make sure to clear your browser cache or bump Splunk to see the chance since this is client-side fix.

This version isn't yet certified for Splunk Cloud so you will need to self-install it for now.

0 Karma

bschaap
Path Finder

Thank you. I updated to 3.0.3 which has fixed the problem with the CSV’s not appearing. The Health / Status and Health / Logs screens are still experiencing the issue described above.

0 Karma

LukeMurphey
Champion

Try running a search in the search page for the following:

index=_internal (sourcetype=lookup_editor_rest_handler OR sourcetype=lookup_backups_rest_handler)

If you don't see anything, then it is likely you don't have permission to search the _internal index.

0 Karma

bschaap
Path Finder

Nothing returns for the search you provided. However, results are returned for the following search.

index=internal sourcetype=lookup* | stats count by sourcetype

Results
lookup_backups_rest_handler-too_small 16
lookup_editor_rest_handler-too_small 53

One issue I notice with these events is that don't seem to include time zone information which causes _time to adjust to the wrong time zone. My user settings are UTC -4:00 which causes new data to show as being recorded 4 hours ago.

0 Karma

LukeMurphey
Champion

You may want to try version 3.0.4. I found an issue where the app is incompatible with at least one other app that had copied some of the Lookup Editor code but hadn't changed the Python module name.

0 Karma

bschaap
Path Finder

I reached out to Splunk Support who informed me that an older version of the Lookup Editor was approved for Splunk Cloud even though it doesn't state this on Splunkbase. It was also mentioned that I could perform a self-service install of the Lookup Editor. I performed the install and discovered that 3.0.2 was installed (not the older version). I will ask Splunk Support to install the older version for me.

0 Karma

Azeemering
Builder

The latest lookup editor version 3.0.2 is not yet available / compatible with Splunk Cloud.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...