Monitoring Splunk

The lookup table does not exist or is not available.

astatrial
Contributor

Hi everyone,

I have an error on my splunk with the below description:

"The lookup table '*' does not exist or is not available."

The lookup name is not mentioned, and the only thing I have is the '*'.

Can you please help me with ways to troubleshoot this, so I will be able to know the name of the lookup and try to figure out where it is used? 

I have looked both in the _internal and the _audit indexes but couldn't find much.

Thanks 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Where is the error being reported?

0 Karma

astatrial
Contributor

I see it in the _internal index:

This is the full message:

01-04-2022 00:00:00.550 +0000 ERROR CsvDataProvider [3333 TcpChannelThread] - The lookup table '*' does not exist or is not available.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...