Splunk Dev

Splunk API seach results - certain lookup returns empty, while others are functioning

eshcharc
Explorer

Hello all,

I use Splunk API in order to export an SPL search.
All queries are working well on my local dev environment and most work on production server.

All queries that include or read from a certain query (let's call it "SessionEntities") seem to return empty.

For instance the query, " | inputlookup  SessionEntities", returns empty.

The same query works both localy and even stranger, works on Splunk search page on the same server, while with the same query and different lookup, it returns with results.

That lookup is no different than the others (no bigger content size), but still.

Anyone has an idea of why could this be happening?

0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Is the lookup visible to the user you are authenticating with for the API call?

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Is the lookup visible to the user you are authenticating with for the API call?

eshcharc
Explorer

@ITWhisperer  Double checked, and it was indeed an issue of permissions of the lookup transform

A big thank from me for helping!

0 Karma

eshcharc
Explorer

It seems to be no different than other working lookups on the same application. What else can I check other than the lookup's application permissions?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...