Knowledge Management

The lookup table XYZ does not exist or not available Error

Roy_9
Motivator

Hello,

I am seeing the below error in the internal logs.
The lookup table XYZ does not exist or not available

I have checked in Lookup table files, Lookup definitions, Automatic Lookups but didn't find this lookup.How do i need to get rid of this error, any suggestions please.

 

Thanks

Labels (3)
0 Karma

Roy_9
Motivator

Ok thank you, I have a problem with another lookup 
| inputlookup test
the lookup table file and definition both are available, both of the permissions are set to read(everyone)- set to app level, but when i am trying to inputlookup i am seeing the error

The lookup table 'test' requires a .csv or KV store lookup definition.
The lookup table 'test' is invalid.


0 Karma

Roy_9
Motivator

@inventsekar  Do you have any idea on the below issue?

| inputlookup test
the lookup table file and definition both are available, both of the permissions are set to read(everyone)- set to app level, but when i am trying to inputlookup i am seeing the error.

Initially the lookup definition is set to read everyone and lookup file is set to read admin, so i changed it to everyone and tried the below search but getting below error

| inputlookup test



The lookup table 'test' requires a .csv or KV store lookup definition.
The lookup table 'test' is invalid.

 

 

Thanks

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Roy_9 ... same like that other macro issue... you should try to find out which search query/report/alert/dashboard is using that lookup's name and update that. 

let us know if you are unable to find out that  search query/report/alert/dashboard, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

Roy_9
Motivator

Thanks @inventsekar 

I tried but no luck, Can you help me with the query to find out the search query/report/alert/dashboard where this lookup is used?

May be I am doing wrong, please help me with the query.

 

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Settings ---> All Configurations

select ...App (all) and Owner (any)... in the text box, enter the lookup name. search it and update us what happens, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...