Getting Data In

Dashboard

808antwon
New Member

Hey all, 

I am running into an issue on one of my dashboards. The issue in questions states "could not load lookup= LOOKUP - user_account_control_property. This issue is persisting across multiple queries within the given dashboard. A previous thread stated to comment out user_account_control_property in default/transforms and prop files. I don't know where those are located. Thanks for helping a Splunk newb. 

 

Also I tried to edit the entry for this lookup in the "Automatic Lookups" but that remedy the issue. 

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @808antwon ,

this lookup is in the Splunk_TA_Windows add-on.

at this url, https://community.splunk.com/t5/Deployment-Architecture/Why-this-error-on-search-head-cluster-after-... you can find a solution/workaround to your issue.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...