Splunk Cloud Platform

Splunk external lookup data viewable only in Search and Reporting

SplunkExplorer
Contributor

Hi Splunkers, for our customer we need to populate an external lookup. We are on a Splunk SaaS env.
A colleague has developed a simple app to achieve this purpose. After some test, the lookup seems to be populated fine.
Our current problem is: if we use this lookup in a search executed from Search and Reporting app, it return expected results. No issue, no missing data. But, if we try from another app able to execute a search (I mean, with search function available), on the same data set and time range, output is empty. We suspect it's related to a permission problem (may be the app has no permission to write on underlying file system, due we are in a cloud env?),  but we are not sure. Moreover, even if we are right how could be fix the issue? 

0 Karma

tej57
Contributor

Hey @SplunkExplorer ,

As you mentioned, it indeed is a permission issue. The lookup might be created within the search app context and the permission might not be shared to access the lookup within different app context. You can update the permission of the KO to be shared globally and it should resolve your concern.

tej57_0-1714399453834.png

 

Thanks,
Tejas.

 

---

If the above solution helps, an upvote is appreciated.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...