Can someone explain why when I create a lookup file does my windows instance of Splunk provide the user name in the audittrail log but on my linux instance the user name is "N/A"? Is there a way to ensure the user name is captured in audittrail when a user creates a lookup file?
are you creating lookup from Splunk settings or lookup editor?
Via the outputlookup command