Knowledge Management

The lookup table XYZ does not exist or not available Error

Roy_9
Motivator

Hello,

I am seeing the below error in the internal logs.
The lookup table XYZ does not exist or not available

I have checked in Lookup table files, Lookup definitions, Automatic Lookups but didn't find this lookup.How do i need to get rid of this error, any suggestions please.

 

Thanks

Labels (3)
0 Karma

Roy_9
Motivator

Ok thank you, I have a problem with another lookup 
| inputlookup test
the lookup table file and definition both are available, both of the permissions are set to read(everyone)- set to app level, but when i am trying to inputlookup i am seeing the error

The lookup table 'test' requires a .csv or KV store lookup definition.
The lookup table 'test' is invalid.


0 Karma

Roy_9
Motivator

@inventsekar  Do you have any idea on the below issue?

| inputlookup test
the lookup table file and definition both are available, both of the permissions are set to read(everyone)- set to app level, but when i am trying to inputlookup i am seeing the error.

Initially the lookup definition is set to read everyone and lookup file is set to read admin, so i changed it to everyone and tried the below search but getting below error

| inputlookup test



The lookup table 'test' requires a .csv or KV store lookup definition.
The lookup table 'test' is invalid.

 

 

Thanks

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Roy_9 ... same like that other macro issue... you should try to find out which search query/report/alert/dashboard is using that lookup's name and update that. 

let us know if you are unable to find out that  search query/report/alert/dashboard, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

Roy_9
Motivator

Thanks @inventsekar 

I tried but no luck, Can you help me with the query to find out the search query/report/alert/dashboard where this lookup is used?

May be I am doing wrong, please help me with the query.

 

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Settings ---> All Configurations

select ...App (all) and Owner (any)... in the text box, enter the lookup name. search it and update us what happens, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...