All Apps and Add-ons

Which version of Lookup Editor App is compatible with Splunk Enterprise 6.4.1?

jincy_18
Path Finder

Hi,

We were using Splunk Enterprise 6.3.2 with Lookup Editor 2.0.3( to view and edit kv-stores) on a 64-bit machine. This is now upgraded to Splunk 6.4.1. We tried two versions of Lookup Editor, faced following issues:
1. Lookup-Editor 2.0.3 :
Sometimes, KV-stores with rows >20, only 20 rows are displayed and remaining rows are not visible (blank background appears)
Gives "Lookups couldn't be loaded" error in clustered environment.
2. Lookup-Editor 2.3.1:
Sometimes, KV-stores with rows >20, only 20 rows are displayed and remaining rows are not visible (blank background appears) and on scrolling down, serial no. are not changed accordingly.
Order of columns is also changed.
For some KV-Stores data is populated randomly, irrespective of the column.

Can you suggest which version of Lookup Editor will be compatible for Splunk 6.4.1 for both standalone and clustered environment?

0 Karma
1 Solution

joao_amorim
Communicator

Sometimes in a row of the KV store, if a field is empty it automatically doesn't populate that field with empty value, so the data from the fields after will be displayed in the wrong place in the Lookup Editor.

Can you check if that's the problem?

Order of columns change or what is changed is the data of that specific column?

Ah also don't forget to check the permissions to that lookup.

Regards

View solution in original post

0 Karma

jincy_18
Path Finder

Please Note: This issue is with the representation in lookup editor only, by using |inputlookup kvstore_name all the fields and values obtained are correct.

0 Karma

joao_amorim
Communicator

Sometimes in a row of the KV store, if a field is empty it automatically doesn't populate that field with empty value, so the data from the fields after will be displayed in the wrong place in the Lookup Editor.

Can you check if that's the problem?

Order of columns change or what is changed is the data of that specific column?

Ah also don't forget to check the permissions to that lookup.

Regards

0 Karma

jincy_18
Path Finder

Thanks for the suggestions, will check for it.
When migrated from lookup editor 2.0.3 to 2.3.1 both order of columns and data in them have shifted randomly.

0 Karma

LukeMurphey
Champion

Did this use to work before the upgrade to Splunk 6.4.1?

0 Karma

jincy_18
Path Finder

Yes with 6.3.2 , lookup-editor 2.0.3 worked fine in both Stand-alone and clustered environment. But with the upgrade to 6.4.1, where we where getting "Lookups couldn't be loaded" error. Hence tried the latest version 2.3.1, which in stand-alone environment itself gave the column-mismatch issue.

Note: KV Stores were populated using the lookup editor 2.0.3 , their corresponding .ns and .0 files in $Splunk_HOME$/var/lib/splunk/kvstore/mongo were directly pushed into clustered environment (6.3.2) and other stand-alone systems.We faced no issues here. Similar process is followed for the 6.4.1.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...