I am running Splunk DB Connect 2 on the only search head in a clustered Environment. I have a Connection to an MS SQL Server Using MS generic driver with Windows authentication. I also have an Identity up and running.
I don't have any problems using either db inputs getting data into Splunk or db outputs.
My issue is that when I want to add a db lookup from the Operations tab, I get the error with db lookups. I have tried to search the internal index for any dbx errors, but I have not found anything out of order.
I'm running Splunk DB Connect 2.1.3 on Splunk 6.2.2 running on a Linux server.
Is there any way I can set up the lookup through inputs.conf, or is there a simpler way to solve this problem?