I wanted to ask you for some help. I am trying to create a lookup table on Splunk. I can’t make it work and I can't figure out why.
Query: | inputlookup TrainingList.csv
The following are the things I did:
Stanza was defined as:
[TrainingList] filename = TrainingList.csv
How are you accessing this lookup table, with query
| inputlookup TrainingList.csv OR
| inputlookup TrainingList?
In which app are you accessing this lookup in Splunk GUI ? For example if you are running above query in
Search & Reporting app and
MyApp has default sharing permission to App level only, then lookup file or lookup definition which created in
MyApp will have app level permission and you will not able to search those lookup files and lookup definitions in other apps. In this case either change
MyApp App permission to Global level with read access to everyone OR change lookup file & lookup definition in
MyApp from App level to Global.
Did you do this through the config files, or the GUI? If you did it through the config files, you will probably need to bounce the Search Head or do a debug refresh: https://answers.splunk.com/answers/102568/reload-transforms-conf-without-restarting-splunk.html