Knowledge Management

The lookup table XYZ does not exist or not available Error

Roy_9
Motivator

Hello,

I am seeing the below error in the internal logs.
The lookup table XYZ does not exist or not available

I have checked in Lookup table files, Lookup definitions, Automatic Lookups but didn't find this lookup.How do i need to get rid of this error, any suggestions please.

 

Thanks

Labels (3)
0 Karma

Roy_9
Motivator

Ok thank you, I have a problem with another lookup 
| inputlookup test
the lookup table file and definition both are available, both of the permissions are set to read(everyone)- set to app level, but when i am trying to inputlookup i am seeing the error

The lookup table 'test' requires a .csv or KV store lookup definition.
The lookup table 'test' is invalid.


0 Karma

Roy_9
Motivator

@inventsekar  Do you have any idea on the below issue?

| inputlookup test
the lookup table file and definition both are available, both of the permissions are set to read(everyone)- set to app level, but when i am trying to inputlookup i am seeing the error.

Initially the lookup definition is set to read everyone and lookup file is set to read admin, so i changed it to everyone and tried the below search but getting below error

| inputlookup test



The lookup table 'test' requires a .csv or KV store lookup definition.
The lookup table 'test' is invalid.

 

 

Thanks

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Roy_9 ... same like that other macro issue... you should try to find out which search query/report/alert/dashboard is using that lookup's name and update that. 

let us know if you are unable to find out that  search query/report/alert/dashboard, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

Roy_9
Motivator

Thanks @inventsekar 

I tried but no luck, Can you help me with the query to find out the search query/report/alert/dashboard where this lookup is used?

May be I am doing wrong, please help me with the query.

 

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Settings ---> All Configurations

select ...App (all) and Owner (any)... in the text box, enter the lookup name. search it and update us what happens, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...