Installation

ERROR AFTER UPGRADING SPLUNK TO LATEST VERSION

khalidewaidah
Explorer

• [RY-SPLUNKID-01] Could not load lookup=LOOKUP-branding_kv_lookup
• [RY-SPLUNKID-01] Could not load lookup=LOOKUP-iris_lookup_history
• [RY-SPLUNKID-01] Could not load lookup=LOOKUP-iris_lookup_queue
• [RY-SPLUNKID-01] Could not load lookup=LOOKUP-whois_lookup_history
• [RY-SPLUNKID-01] Could not load lookup=LOOKUP-whois_lookup_queue
• [RY-SPLUNKID-02] The lookup table 'branding_kv_lookup' does not exist. It is referenced by configuration 'dtoolscsvkv'.
• [RY-SPLUNKID-02] The lookup table 'iris_lookup_history' does not exist. It is referenced by configuration 'dtoolscsvkv'.
• [RY-SPLUNKID-02] The lookup table 'iris_lookup_queue' does not exist. It is referenced by configuration 'dtoolscsvkv'.
• [RY-SPLUNKID-02] The lookup table 'whois_lookup_history' does not exist. It is referenced by configuration 'dtoolscsvkv'.
• [RY-SPLUNKID-02] The lookup table 'whois_lookup_queue' does not exist. It is referenced by configuration 'dtoolscsvkv'.
• [RY-SPLUNKID-03] Could not load lookup=LOOKUP-branding_kv_lookup
• [RY-SPLUNKID-03] Could not load lookup=LOOKUP-iris_lookup_history
• [RY-SPLUNKID-03] Could not load lookup=LOOKUP-iris_lookup_queue
• [RY-SPLUNKID-03] Could not load lookup=LOOKUP-whois_lookup_history
• [RY-SPLUNKID-03] Could not load lookup=LOOKUP-whois_lookup_queue

Tags (1)
0 Karma

woodcock
Esteemed Legend

Could it be this?
https://docs.splunk.com/Documentation/Splunk/7.2.6/Installation/AboutupgradingREADTHISFIRST
It clearly says this:

The use of disabled lookups in searches or other lookups is no longer allowed
You can no longer use a disabled lookup as part of a search or other lookup. After you upgrade, when you attempt to use a disabled lookup, you receive the error message The lookup table '<lookup name>' is disabled.
0 Karma

lakshman239
Influencer

The sourcetype in props.conf is referring to lookup definitions, but unable to read it. Is the above error from a custom app? check the permissions of lookups and definitions in local.meta or via GUI and setup the permissions , ensuring the lookup tables, tranforms.conf all line up.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...