Dashboards & Visualizations

HOW TO REMOVE COULD NOT LOAD LOOKUP ERROR

aditsss
Motivator

Hi Everyone,

My splunk instance has been migrated. When I am searching for the index I am getting Below ERRORS: I FOUND THESE LOOKUPS IN MY AUTOMATIC LOOKUPS. 

I checked the permission. Its GLOBAL only . How can I remove the these Errors.

Can someone guide me on this.

index="ABC"

  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-DASHBOARD1
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-REPORT1
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-USER_AGENT
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-USER_NAME
  • [hvidltwa13] Could not load lookup=LOOKUP-SFDC-USER_NAME1
Labels (1)
0 Karma

Ashwini008
Builder

@aditsss Recently one of our user had faced the same issue. The reason behind that was the UF was not installed Properly.

 Make sure your getting data from the UF to your splunk instance. In our case the outputs.conf on UF was not defined with correct port number. Once the port number defined on outputs.conf was corrected(receiving port number :9997) ,the error was removed.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

you already did the same answer, please see my answers to it https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fix-quot-Could-not-load-lookup-Erro...

ciao.

Giuseppe

0 Karma

aditsss
Motivator

@gcusello 

 

Do I need to reinstall the app or exactly what I need to do . Can you guide me.

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

if your app has a lower version, upgrade it to the last one.

if it has the same version, extract the app files in anothe folder and copy them on the app folder (then restart Splunk).

Ciao.

Giuseppe

0 Karma

aditsss
Motivator

@gcusello 

I am able to see this version when I run below command in search:

| rest /services/apps/local | search disabled=0 core=0|dedup label | table label version

From where I need to compare the version?

EP DevOps1.0.0
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

you have to compare your app version (that you can see also by GUI in [Apps -- Manage Apps -- choose Salesforce apps -- Edit properties] with the one that you can find in apps.splunk.com.

For salesforce apps:

  • Splunk App for Salesforce vers. 3.0.0
  • Splunk Add-On for Salesforce vers. 4.0.2

Ciao.

Giuseppe

0 Karma

aditsss
Motivator
Hi @gcusello The version is fine I checked in another Environment also I am using the same version but its running fine
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aditsss,

have in the other environments the same automatic lookups or not?

you could copy the app from the other environment in the one with errors.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...