Installation

ERROR AFTER UPGRADING SPLUNK TO LATEST VERSION

khalidewaidah
Explorer

• [RY-SPLUNKID-01] Could not load lookup=LOOKUP-branding_kv_lookup
• [RY-SPLUNKID-01] Could not load lookup=LOOKUP-iris_lookup_history
• [RY-SPLUNKID-01] Could not load lookup=LOOKUP-iris_lookup_queue
• [RY-SPLUNKID-01] Could not load lookup=LOOKUP-whois_lookup_history
• [RY-SPLUNKID-01] Could not load lookup=LOOKUP-whois_lookup_queue
• [RY-SPLUNKID-02] The lookup table 'branding_kv_lookup' does not exist. It is referenced by configuration 'dtoolscsvkv'.
• [RY-SPLUNKID-02] The lookup table 'iris_lookup_history' does not exist. It is referenced by configuration 'dtoolscsvkv'.
• [RY-SPLUNKID-02] The lookup table 'iris_lookup_queue' does not exist. It is referenced by configuration 'dtoolscsvkv'.
• [RY-SPLUNKID-02] The lookup table 'whois_lookup_history' does not exist. It is referenced by configuration 'dtoolscsvkv'.
• [RY-SPLUNKID-02] The lookup table 'whois_lookup_queue' does not exist. It is referenced by configuration 'dtoolscsvkv'.
• [RY-SPLUNKID-03] Could not load lookup=LOOKUP-branding_kv_lookup
• [RY-SPLUNKID-03] Could not load lookup=LOOKUP-iris_lookup_history
• [RY-SPLUNKID-03] Could not load lookup=LOOKUP-iris_lookup_queue
• [RY-SPLUNKID-03] Could not load lookup=LOOKUP-whois_lookup_history
• [RY-SPLUNKID-03] Could not load lookup=LOOKUP-whois_lookup_queue

Tags (1)
0 Karma

woodcock
Esteemed Legend

Could it be this?
https://docs.splunk.com/Documentation/Splunk/7.2.6/Installation/AboutupgradingREADTHISFIRST
It clearly says this:

The use of disabled lookups in searches or other lookups is no longer allowed
You can no longer use a disabled lookup as part of a search or other lookup. After you upgrade, when you attempt to use a disabled lookup, you receive the error message The lookup table '<lookup name>' is disabled.
0 Karma

lakshman239
Influencer

The sourcetype in props.conf is referring to lookup definitions, but unable to read it. Is the above error from a custom app? check the permissions of lookups and definitions in local.meta or via GUI and setup the permissions , ensuring the lookup tables, tranforms.conf all line up.

0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...