All Apps and Add-ons

Why am I receiving lookup error "could not find the specified lookup fields in the lookup table : endpoint_change_status_lookup"?

saurabh_tek
Communicator

alt text

Hello Splunkers,

I am facing this strange error since the time i have installed Palo Alto Networks App for Splunk. This error is coming to every search in all pre-built and custom apps in Splunk. I tried to figure out why its coming and how to solve this but no luck.

Can anyone please help me get rid of this?

0 Karma
1 Solution

btorresgil
Builder

Hello,

That lookup table (endpoint_change_status_lookup) doesn't exist in the PAN App or Add-on. Most likely there is something you've created in a props.conf or transforms.conf that creates a lookup called "endpoint_change_status_lookup". This lookup table seems to be missing a field or not exist.

I recommend doing a find across all files in your splunk directory for the lookup table name: endpoint_change_status_lookup

Find where this lookup table is configured and remove it or add the necessary fields that are causing the error.

View solution in original post

0 Karma

btorresgil
Builder

Hello,

That lookup table (endpoint_change_status_lookup) doesn't exist in the PAN App or Add-on. Most likely there is something you've created in a props.conf or transforms.conf that creates a lookup called "endpoint_change_status_lookup". This lookup table seems to be missing a field or not exist.

I recommend doing a find across all files in your splunk directory for the lookup table name: endpoint_change_status_lookup

Find where this lookup table is configured and remove it or add the necessary fields that are causing the error.

0 Karma

saurabh_tek
Communicator

you are right, this was coming from another app blueliv, we corrected it and its fine now. Thanks @btorresgil for prompt response.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...