Knowledge Management

search lookup errors

Dmitriy
Explorer

Hello, when i search from index=alfa_cisco_ice and see the errors:

AutoLookupDriver - Could not load lookup='LOOKUP-cisco_asa_ids_lookup' reason='Error in 'lookup' command: Must specify one or more lookup fields.'

Please help, how too fix this problem? 

And in inspector i see alot of log like 

SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='cisco_dest_ipv6'.

 

SearchOperator:kv - Invalid key-value parser, ignoring it, transform_name='cisco_fw_connection'

 

Dmitriy_0-1628682532647.png

 

Labels (1)
Tags (1)
0 Karma

Dmitriy
Explorer

i found the first problem Automatic lookups  this 

'LOOKUP-cisco_asa_ids_lookup'

use app TA-alfa_firepower and permited for all app i change permissions for TA-alfa_firepower only. is this good idea?

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...