All Apps and Add-ons

Palo Alto Networks App for Splunk: How to regenerate the lookup table from disk?

skjennings
Explorer

We are getting the following error when we run queries:
The lookup table 'pan_vendor_info_lookup' does not exist. It is referenced by configuration 'pan:newapps'.

Looks like someone deleted the lookup table in the Splunk instance but it still exists on the disk. I just do not know how to have it generate the table and definition.

Note: I tried to reinstall the add on but no luck

0 Karma
1 Solution

skjennings
Explorer

We had to remove the Splunk Application and Add-on. The previous admins had custom parsing scripts.

View solution in original post

0 Karma

skjennings
Explorer

We had to remove the Splunk Application and Add-on. The previous admins had custom parsing scripts.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@skjennings, if your problem is resolved, please accept an answer to help future users.

---
If this reply helps you, Karma would be appreciated.
0 Karma

skjennings
Explorer

The answer would not show for me after I first submitted it.

0 Karma

DalJeanis
Legend

If nothing else, you can download the table to another box, then use settings>Lookups>Lookup table files to upload it again in the appropriate app, and settings>Lookup>Lookup definitions to define it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...