All Apps and Add-ons

Splunk Add-on for Microsoft IIS lookup issue on indexers

splunk_user4
Explorer

I have just updated the Splunk Add-on for Microsoft IIS and am hit with this issue with every search I run now

Could not load lookup=LOOKUP-iis_action_lookup 

[indexer1] Could not load lookup=LOOKUP-iis_action_lookup

[indexer2] Could not load lookup=LOOKUP-iis_action_lookup

[indexer3] Could not load lookup=LOOKUP-iis_action_lookup

ect..

The upgrade was from version 1.0.1-1.20, I am running on a linux splunk environment with a SH cluster and an Index Cluster.  The issue itself seems straight forward but I confirmed the lookup is on each indexer, and on the deployer .../master-apps/Splunk_TA_microsoft-iis/lookups.  Each application version matches on all search heads and indexers.

Labels (3)
0 Karma

billshayne
New Member

I'm having the same issue, were you able to fix yours ?

 

0 Karma

jaredthomason
Explorer

Did you ever figure this out?

0 Karma

Bazza_12
Path Finder

Same after upgrading versions - app not on indexer as on HF

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...