Hey all,
I am running into an issue on one of my dashboards. The issue in questions states "could not load lookup= LOOKUP - user_account_control_property. This issue is persisting across multiple queries within the given dashboard. A previous thread stated to comment out user_account_control_property in default/transforms and prop files. I don't know where those are located. Thanks for helping a Splunk newb.
Also I tried to edit the entry for this lookup in the "Automatic Lookups" but that remedy the issue.
Hi @808antwon ,
this lookup is in the Splunk_TA_Windows add-on.
at this url, https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-... you can find a solution/workaround to your issue.
Ciao.
Giuseppe