Splunk Dev

Unable to delete automatic lookup

aphextwin
New Member

Hi Folks

I've created a new lookup for Windows event 680 and applied it successfully. This morning, due to some other admin's actions the look up stopped working and troubleshooting it didnt bear any fruit.

I've decided to clear the slate and start fresh - but after removing the lookup table and definition, I am unable to remove the entry from the "Automatic Lookup" list.

Error Quoted:

*Error occurred attempting to remove '680-lookup-auto' In handler
'props-lookup': Object
'680-lookup-auto' does not
exist in user=admin, app=search:
props.conf

Checked props.conf and sure enough it's not listed. Need to have it removed as every normal search will return errors on the main page refering to the auto-lookup.

Any help would be appreciated.

Tags (1)
0 Karma

Drainy
Champion

Which props.conf have you checked?
Possible locations for it could be;

SPLUNK_HOME/etc/apps/search/local/
SPLUNK_HOME/etc/users/USERNAME/APP/local/  <- could be the search app here
SPLUNK_HOME/etc/system/local/

A nice quick way to check is to run the following command in the SPLUNK_HOME/bin directory;

Linux - ./splunk cmd btool props list --debug

Windows - splunk cmd btool props list --debug

This will list all the lines from props.conf it has read in and prefix it with the name of the app applying it.

Drainy
Champion

No problem, glad it helped 🙂 Feel free to click on the tick to the left of my answer, it will just mark this as the right answer for anyone with the same problem in the future.

0 Karma

aphextwin
New Member

thanks for that mate! the debug tool helped!
found the reference, removed it, restarted and i was able to remove it from the autolookup list.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...