All Apps and Add-ons

Palo Alto Networks App for Splunk: How to regenerate the lookup table from disk?

skjennings
Explorer

We are getting the following error when we run queries:
The lookup table 'pan_vendor_info_lookup' does not exist. It is referenced by configuration 'pan:newapps'.

Looks like someone deleted the lookup table in the Splunk instance but it still exists on the disk. I just do not know how to have it generate the table and definition.

Note: I tried to reinstall the add on but no luck

0 Karma
1 Solution

skjennings
Explorer

We had to remove the Splunk Application and Add-on. The previous admins had custom parsing scripts.

View solution in original post

0 Karma

skjennings
Explorer

We had to remove the Splunk Application and Add-on. The previous admins had custom parsing scripts.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@skjennings, if your problem is resolved, please accept an answer to help future users.

---
If this reply helps you, Karma would be appreciated.
0 Karma

skjennings
Explorer

The answer would not show for me after I first submitted it.

0 Karma

DalJeanis
Legend

If nothing else, you can download the table to another box, then use settings>Lookups>Lookup table files to upload it again in the appropriate app, and settings>Lookup>Lookup definitions to define it.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...