Installation

Why do I get the following error after upgrading Splunk to 7.2?

graju89
Path Finder

I get the following error after upgrading to Splunk 7.2.

The error is:

Could not load lookup=LOOKUP-minemeldfeeds_dest_lookup
Could not load lookup=LOOKUP-minemeldfeeds_src_lookup

I have only upgraded my search head. Other instances are running 6.6.6.

Can anyone can help me?

Tags (1)
0 Karma
1 Solution

graju89
Path Finder

If anyone having same issue.

The problem was fixed by downgrading splunk to 7.1.1. Probably splunk PAN add-on(6.0.2) is not compatible with splunk7.2. I havent tried upgrading PAN add-on to 6.1.0 though.

View solution in original post

0 Karma

Rob2520
Communicator
0 Karma

graju89
Path Finder

If anyone having same issue.

The problem was fixed by downgrading splunk to 7.1.1. Probably splunk PAN add-on(6.0.2) is not compatible with splunk7.2. I havent tried upgrading PAN add-on to 6.1.0 though.

0 Karma

vinkumar_splunk
Splunk Employee
Splunk Employee

This lookup comes from Palo Alto app, check whether the below link is helpful. Check app compatibility as well.

https://answers.splunk.com/answers/590248/error-at-search-time-after-upgrading-palo-alto-net-1.html

0 Karma

graju89
Path Finder

@vinkumar_splunk I tried that. Still no luck. And the add-on has no compatibility issue.

0 Karma

graju89
Path Finder

Also, search peers are reporting this error
The 'minemeldfeeds_lookup' KV Store lookup table is empty or has not yet been replicated to the search peer.
I dont know why it is reporting after I upgrade. search peers are running 6.6.6 and search head is running 7.2.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...