I have recently ingested Cisco Umbrella logs into Splunk Cloud (8.1.2) and everything seems to be working fine, expect for the Network Resolution DNS data model. When I try to accelerate the model or pivot, I obtain the following errrors:
1) The search job has failed due to an error. You may be able view the job in the job inspector
2) Error in 'lookup' command: Could not construct lookup 'cim_dns_reply_code_lookup, reply_code_id, AS, reply_code_id, OUTPUT, reply_code, AS, reply_code'. See search.log for more details.
3) Cannot expand lookup field 'action' due to a reference cycle in the lookup configuration. Rewrite the lookup configuration to remove the reference cycle.
I reviewed the search.log but don't see anything related to causing the issue. Has anyone experienced or solved this before?