Dashboards & Visualizations

HOW TO REMOVE COULD NOT LOAD LOOKUP ERROR

aditsss
Motivator

Hi Everyone,

My splunk instance has been migrated. When I am searching for the index I am getting Below ERRORS: I FOUND THESE LOOKUPS IN MY AUTOMATIC LOOKUPS. 

I checked the permission. Its GLOBAL only . How can I remove the these Errors.

Can someone guide me on this.

index="ABC"

  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-DASHBOARD1
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-REPORT1
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-USER_AGENT
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-USER_NAME
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-USER_NAME1
Labels (1)
0 Karma

Ashwini008
Builder

@aditsss Recently one of our user had faced the same issue. The reason behind that was the UF was not installed Properly.

 Make sure your getting data from the UF to your splunk instance. In our case the outputs.conf on UF was not defined with correct port number. Once the port number defined on outputs.conf was corrected(receiving port number :9997) ,the error was removed.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

you already did the same answer, please see my answers to it https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fix-quot-Could-not-load-lookup-Erro...

ciao.

Giuseppe

0 Karma

aditsss
Motivator

@gcusello 

 

Do I need to reinstall the app or exactly what I need to do . Can you guide me.

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

if your app has a lower version, upgrade it to the last one.

if it has the same version, extract the app files in anothe folder and copy them on the app folder (then restart Splunk).

Ciao.

Giuseppe

0 Karma

aditsss
Motivator

@gcusello 

I am able to see this version when I run below command in search:

| rest /services/apps/local | search disabled=0 core=0|dedup label | table label version

From where I need to compare the version?

EP DevOps1.0.0
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

you have to compare your app version (that you can see also by GUI in [Apps -- Manage Apps -- choose Salesforce apps -- Edit properties] with the one that you can find in apps.splunk.com.

For salesforce apps:

  • Splunk App for Salesforce vers. 3.0.0
  • Splunk Add-On for Salesforce vers. 4.0.2

Ciao.

Giuseppe

0 Karma

aditsss
Motivator
Hi @gcusello The version is fine I checked in another Environment also I am using the same version but its running fine
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

have in the other environments the same automatic lookups or not?

you could copy the app from the other environment in the one with errors.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...