Reporting

error while creating a pivot in splunk 6 tutorial

Radu3000
Engager

I am new to splunk. After installing it I have tried the Splunk-6.0-PivotTutoria.pdf - upto this point:

  1. Select "Purchase Requests". This opens a New Pivot editor for the Purchase Requests object.

But then I am getting this error:

The search job has failed due to an
error. You may be able view the job in
the Job Inspector. Share Export Print
Open in Search Starting job... Error
in 'lookup' command: Could not find
all of the specified destination
fields in the lookup table.

Can you please help.

thanks,
Radu

Tags (3)
0 Karma

mattness
Splunk Employee
Splunk Employee

Looks like you may have defined your lookup attributes incorrectly. Go back to Part 4 of the tutorial and check to make sure that you have added your lookup attributes correctly in the "Edit attributes list" topic. When you set up the lookup attribute you should always click Preview to ensure that it is adding the Price and ProductName fields to your data. If it isn't, you have some troubleshooting to do. The first troubleshooting step you should take to is make sure that the price_lookup has been correctly set up, which you do here.

mattness
Splunk Employee
Splunk Employee

The easiest thing to do in that case might be to just use the Send Feedback button at the bottom of the Data Model Tutorial topics that had discrepancies.

Radu3000
Engager

Thanks for your answer - I have moved a bit further (had to basically restart) through the tutorial - but got stuck on charts section.

The tutorial gives an idea what and how it can be accomplished... for a user that has splunk experience already. However it lacks accuracy in a few places - and a novice would always go back to support. Can you please improve it? I can provide the discrepancies - offline.

Thanks,
Radu

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...