I believe the 8.6 version is missing a few default lookups. I receive an error about unable to find "nix_fs_notification_change_type" lookup whenever we search. if you look at the doc and compare it to the \Splunk_TA_nix\lookups dir, there are at least 5 lookups missing. In 8.5 all 10 lookups are present.
I suggest maybe copying the missing lookups or just staying on 8.5.