Dashboards & Visualizations

HOW TO REMOVE COULD NOT LOAD LOOKUP ERROR

aditsss
Motivator

Hi Everyone,

My splunk instance has been migrated. When I am searching for the index I am getting Below ERRORS: I FOUND THESE LOOKUPS IN MY AUTOMATIC LOOKUPS. 

I checked the permission. Its GLOBAL only . How can I remove the these Errors.

Can someone guide me on this.

index="ABC"

  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-DASHBOARD1
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-REPORT1
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-USER_AGENT
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-USER_NAME
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-USER_NAME1
Labels (1)
0 Karma

Ashwini008
Builder

@aditsss Recently one of our user had faced the same issue. The reason behind that was the UF was not installed Properly.

 Make sure your getting data from the UF to your splunk instance. In our case the outputs.conf on UF was not defined with correct port number. Once the port number defined on outputs.conf was corrected(receiving port number :9997) ,the error was removed.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

you already did the same answer, please see my answers to it https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fix-quot-Could-not-load-lookup-Erro...

ciao.

Giuseppe

0 Karma

aditsss
Motivator

@gcusello 

 

Do I need to reinstall the app or exactly what I need to do . Can you guide me.

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

if your app has a lower version, upgrade it to the last one.

if it has the same version, extract the app files in anothe folder and copy them on the app folder (then restart Splunk).

Ciao.

Giuseppe

0 Karma

aditsss
Motivator

@gcusello 

I am able to see this version when I run below command in search:

| rest /services/apps/local | search disabled=0 core=0|dedup label | table label version

From where I need to compare the version?

EP DevOps1.0.0
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

you have to compare your app version (that you can see also by GUI in [Apps -- Manage Apps -- choose Salesforce apps -- Edit properties] with the one that you can find in apps.splunk.com.

For salesforce apps:

  • Splunk App for Salesforce vers. 3.0.0
  • Splunk Add-On for Salesforce vers. 4.0.2

Ciao.

Giuseppe

0 Karma

aditsss
Motivator
Hi @gcusello The version is fine I checked in another Environment also I am using the same version but its running fine
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

have in the other environments the same automatic lookups or not?

you could copy the app from the other environment in the one with errors.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...