All Apps and Add-ons

lookup error in splunk threathunting app

sabaKhadivi
Path Finder

Error in 'lookup' command: Could not construct lookup 'dns_whitelist, mitre_technique_id, host_fqdn, process_path, query_name, output, reason'. See search.log for more details.

I get this error in threat hunting app , and when I fill lookup fields the problem still stays, whats the solution.

mcbradford
Contributor

This is what I did to resolve the errors.  Within the app, click the whitelist pulldown, and then select each whitelist, and start populating.  I used blah data and after doing this, I no longer was seeing the errors.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What are you doing when this error occurs?
What details do you find in search.log?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...