Deployment Architecture

distributed search error

DTERM
Contributor

I;ve setup a search head with a custom app I've created. The search head appears to work. That is, it answers the queries and produces the charts and graphs remotely. However I get the following error on every execution within the application.

[splunk] The lookup table 'wksh_action_lookup' does not exist. It is referenced by configuration 'syslog'.

What does that mean? How to fix it? Thanks.

Tags (1)
0 Karma
1 Solution

DTERM
Contributor

This was an error fixed by chown....

View solution in original post

0 Karma

DTERM
Contributor

This was an error fixed by chown....

0 Karma