Splunk Cloud Platform

How to resolve error: cannot expand lookup field 'hostname' due to a reference cycle in the lookup configuration

lukmanfikri
New Member

Hi

I got error message after upgrading splunk enterprise from version 8.1 to version 8.2.7

in all my splunk dashboard, it shows warning with message : cannot expand lookup field 'hostname' due to a reference cycle in the lookup configuration

can you tell me how to fix this issue?

 

thank you

Labels (2)
Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @lukmanfikri ... At the end of this post, there is a good step by step method.. pls check it out...

https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-can-I-not-expand-lookup-field-due-to-a-ref...

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@lukmanfikri - This situation occurs when lookup definition configured badly. Detailed about it documented here - https://docs.splunk.com/Documentation/Splunk/9.0.1/Knowledge/DefineanautomaticlookupinSplunkWeb ("Avoid creating automatic lookup reference cycles")

 

You can troubleshoot by greping for "LOOKUP" and "hostname" under all props.conf definition.

 

I hope this helps!!!

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...