Hi,
In Splunk 6.4.5 standalone on Windows. After creating an app, I added a stanza in transforms.conf and collections.conf in default folder. Then after adding few entries in that KV Store i am able to see through |inputlookup
command
Then i added transforms.conf and collections.conf in the local folder of the app and then added stanza for KV Store, but when i tried |inputlookup
command it gives me error as "The lookup table is invalid".
Please advise.
Finally issue is resolved now. It was permission issue on my windows as suggested.
On Splunk Folder >Propperties>Security Tab>Advanced>In Advanced Security Settings>Given Full Control Access for particular User-Admin and tick on checkbox-"Replace all child object permission entries with inheritable permission entries from this object".
Then Apply these settings.
Thanks @MuS @woodcock and @mattymo