Splunk Cloud Platform

Splunk external lookup data viewable only in Search and Reporting

SplunkExplorer
Contributor

Hi Splunkers, for our customer we need to populate an external lookup. We are on a Splunk SaaS env.
A colleague has developed a simple app to achieve this purpose. After some test, the lookup seems to be populated fine.
Our current problem is: if we use this lookup in a search executed from Search and Reporting app, it return expected results. No issue, no missing data. But, if we try from another app able to execute a search (I mean, with search function available), on the same data set and time range, output is empty. We suspect it's related to a permission problem (may be the app has no permission to write on underlying file system, due we are in a cloud env?),  but we are not sure. Moreover, even if we are right how could be fix the issue? 

0 Karma

tej57
Builder

Hey @SplunkExplorer ,

As you mentioned, it indeed is a permission issue. The lookup might be created within the search app context and the permission might not be shared to access the lookup within different app context. You can update the permission of the KO to be shared globally and it should resolve your concern.

tej57_0-1714399453834.png

 

Thanks,
Tejas.

 

---

If the above solution helps, an upvote is appreciated.

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...