All Apps and Add-ons

Why is Splunk Add-on for Unix and Linux 8.6 missing lookups?

Markt13
Engager

I believe the 8.6 version is missing a few default lookups. I receive an error about unable to find "nix_fs_notification_change_type" lookup whenever we search.  if you look at the doc and compare it to the \Splunk_TA_nix\lookups dir, there are at least 5 lookups missing.  In 8.5 all 10 lookups are present. 

https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Lookups.

I suggest maybe copying the missing lookups or just staying on 8.5. 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...