All Apps and Add-ons

Minemeld Lookup errors after upgrading Splunk to 7.2

matthewfry
Explorer

Splunk version: 7.2.1
Palo Alto App version: 6.1

I am getting the following errors after the upgrade:

Could not load lookup=LOOKUP-minemeldfeeds_dest_lookup
Could not load lookup=LOOKUP-minemeldfeeds_src_lookup

The Splunkbase page for the Palo Alto app says 6.1 is compatible with 7.2... so what gives? How can I clear this error? I have found no answers for this on Splunk Answers or on Google.

0 Karma
1 Solution

matthewfry
Explorer

Okay I have found my own answer. This ended up being a KVStore issue. The resolution was to run the following command on my SearchHead:

./splunk migrate migrate-kvstore

Here is the article that helped me to this conclusion:

https://answers.splunk.com/answers/690118/why-is-the-kv-store-process-failing-after-upgrade.html

View solution in original post

0 Karma

matthewfry
Explorer

Okay I have found my own answer. This ended up being a KVStore issue. The resolution was to run the following command on my SearchHead:

./splunk migrate migrate-kvstore

Here is the article that helped me to this conclusion:

https://answers.splunk.com/answers/690118/why-is-the-kv-store-process-failing-after-upgrade.html

0 Karma

matthewfry
Explorer

Also get this in the Palo Alto dashboards:

Error in 'lookup' command: Lookups: Could not construct lookup 'minemeldfeeds_lookup, indicator, AS, client_ip, OUTPUT, value.autofocus_tags, AS, client_autofocus_tags'. See search.log for more details.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...