All Apps and Add-ons

iSeries/as400 app lookup table error after upgrading to 5.0.2

mraimo
Explorer

We upgraded Splunk yesterday from 4.2.3 to 5.0.2 and have consistently received the error "[server name] The lookup table 'jrn _ detail _ lookup' does not exist. It is referenced by configuration 'dspjrn:5'.

The error appears within any apps that I go into (i.e. Cisco, Windows, iSeries). I have tried to upgrade the iSeries app, but the error still appears. Any suggestions? Thanks!

*Update...we recently upgraded to 5.0.2.2 after having other issues with the system. The error still appears even though I can see the lookup table in the app config.

0 Karma
1 Solution

JSapienza
Contributor

To fix this issue, edit $SPLUNK_HOME/etc/apps/iseries/metadata/local.meta

and, edit following:

[lookups] 

export = system 

This worked for me.

View solution in original post

JSapienza
Contributor

To fix this issue, edit $SPLUNK_HOME/etc/apps/iseries/metadata/local.meta

and, edit following:

[lookups] 

export = system 

This worked for me.

mraimo
Explorer

Thank you! It appears to be working for me as well.

0 Karma

dondky
Path Finder

BTW this is an iseries lookup issue. I don't think the dspjrn lookup is in cisco or anything else. I think this question would be better off if it was titled iseries lookup or as400 app related.

0 Karma

dondky
Path Finder

Me three, haven't found a solution to this as well. Perhaps the author can chime in.

0 Karma

mraimo
Explorer

We still have not found an answer to this solution. I have tried other fixes from the 4.1 upgrade however it did not fix the issue. If I find a solution that works I will make sure to post it in here since it seems to be a problem with multiple users.

0 Karma

afaraino
Explorer

Got the same error since upgraded to 5.0.2.
Still looking...

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...