Monitoring Splunk

Could not load lookup=LOOKUP-itsi_kpi_attributes?

domino30
Path Finder

first1.PNG

 so it says Could not load lookup=LOOKUP-itsi_kpi_attributes 

second.PNG

 looking around find there are pointers i think.

fourth.PNG

but if i click on lookup table files and filter for  itsi_kpi_attributes  i get --->

domino30_0-1660771767400.png

wait last one 

fith.PNG

If this says none what's worse this says none or no csv even though I see some pointer to a field that doesn't exist.

 

if I am right where is this file? if not # is what I am asking making sense #2 is there something else you'd like to see if so tell me where it is thanks.

Labels (2)
Tags (2)
0 Karma

joy
Splunk Employee
Splunk Employee

On snippet showing Hosts dashboard, it may be due to permissions. Try going to the search of that Monitoring Link app, and see if you get anything if you run the search: | inputlookup itsi_kpi_attributes

On snippet showing no results from searching Lookup Table File, on top of having "itsi_kpi_attributes" as a filter, you are also filtering to App=InfoSec (InfoSec_A...), remove that App filter.

Try to run the | inputlookup itsi_kpi_attributes from the same app where the dashboard is, and see if you get any records.

0 Karma
Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...