Knowledge Management

The lookup table XYZ does not exist or not available Error

Roy_9
Motivator

Hello,

I am seeing the below error in the internal logs.
The lookup table XYZ does not exist or not available

I have checked in Lookup table files, Lookup definitions, Automatic Lookups but didn't find this lookup.How do i need to get rid of this error, any suggestions please.

 

Thanks

Labels (3)
0 Karma

Roy_9
Motivator

Ok thank you, I have a problem with another lookup 
| inputlookup test
the lookup table file and definition both are available, both of the permissions are set to read(everyone)- set to app level, but when i am trying to inputlookup i am seeing the error

The lookup table 'test' requires a .csv or KV store lookup definition.
The lookup table 'test' is invalid.


0 Karma

Roy_9
Motivator

@inventsekar  Do you have any idea on the below issue?

| inputlookup test
the lookup table file and definition both are available, both of the permissions are set to read(everyone)- set to app level, but when i am trying to inputlookup i am seeing the error.

Initially the lookup definition is set to read everyone and lookup file is set to read admin, so i changed it to everyone and tried the below search but getting below error

| inputlookup test



The lookup table 'test' requires a .csv or KV store lookup definition.
The lookup table 'test' is invalid.

 

 

Thanks

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Roy_9 ... same like that other macro issue... you should try to find out which search query/report/alert/dashboard is using that lookup's name and update that. 

let us know if you are unable to find out that  search query/report/alert/dashboard, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

Roy_9
Motivator

Thanks @inventsekar 

I tried but no luck, Can you help me with the query to find out the search query/report/alert/dashboard where this lookup is used?

May be I am doing wrong, please help me with the query.

 

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Settings ---> All Configurations

select ...App (all) and Owner (any)... in the text box, enter the lookup name. search it and update us what happens, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...