Monitoring Splunk

The lookup table does not exist or is not available.

astatrial
Contributor

Hi everyone,

I have an error on my splunk with the below description:

"The lookup table '*' does not exist or is not available."

The lookup name is not mentioned, and the only thing I have is the '*'.

Can you please help me with ways to troubleshoot this, so I will be able to know the name of the lookup and try to figure out where it is used? 

I have looked both in the _internal and the _audit indexes but couldn't find much.

Thanks 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Where is the error being reported?

0 Karma

astatrial
Contributor

I see it in the _internal index:

This is the full message:

01-04-2022 00:00:00.550 +0000 ERROR CsvDataProvider [3333 TcpChannelThread] - The lookup table '*' does not exist or is not available.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...