I am facing this strange error since the time i have installed Palo Alto Networks App for Splunk. This error is coming to every search in all pre-built and custom apps in Splunk. I tried to figure out why its coming and how to solve this but no luck.
Can anyone please help me get rid of this?
That lookup table (endpointchangestatuslookup) doesn't exist in the PAN App or Add-on. Most likely there is something you've created in a props.conf or transforms.conf that creates a lookup called "endpointchangestatuslookup". This lookup table seems to be missing a field or not exist.
I recommend doing a find across all files in your splunk directory for the lookup table name: endpointchangestatus_lookup
Find where this lookup table is configured and remove it or add the necessary fields that are causing the error.
you are right, this was coming from another app blueliv, we corrected it and its fine now. Thanks @btorresgil for prompt response.