I've created a new lookup for Windows event 680 and applied it successfully. This morning, due to some other admin's actions the look up stopped working and troubleshooting it didnt bear any fruit.
I've decided to clear the slate and start fresh - but after removing the lookup table and definition, I am unable to remove the entry from the "Automatic Lookup" list.
*Error occurred attempting to remove '680-lookup-auto' In handler
'680-lookup-auto' does not
exist in user=admin, app=search:
Checked props.conf and sure enough it's not listed. Need to have it removed as every normal search will return errors on the main page refering to the auto-lookup.
Any help would be appreciated.
Which props.conf have you checked?
Possible locations for it could be;
SPLUNK_HOME/etc/apps/search/local/ SPLUNK_HOME/etc/users/USERNAME/APP/local/ <- could be the search app here SPLUNK_HOME/etc/system/local/
A nice quick way to check is to run the following command in the
Linux - ./splunk cmd btool props list --debug Windows - splunk cmd btool props list --debug
This will list all the lines from props.conf it has read in and prefix it with the name of the app applying it.