Monitoring Splunk

The lookup table does not exist or is not available.

astatrial
Contributor

Hi everyone,

I have an error on my splunk with the below description:

"The lookup table '*' does not exist or is not available."

The lookup name is not mentioned, and the only thing I have is the '*'.

Can you please help me with ways to troubleshoot this, so I will be able to know the name of the lookup and try to figure out where it is used? 

I have looked both in the _internal and the _audit indexes but couldn't find much.

Thanks 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Where is the error being reported?

0 Karma

astatrial
Contributor

I see it in the _internal index:

This is the full message:

01-04-2022 00:00:00.550 +0000 ERROR CsvDataProvider [3333 TcpChannelThread] - The lookup table '*' does not exist or is not available.

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...