Splunk Dev

Unable to delete automatic lookup

aphextwin
New Member

Hi Folks

I've created a new lookup for Windows event 680 and applied it successfully. This morning, due to some other admin's actions the look up stopped working and troubleshooting it didnt bear any fruit.

I've decided to clear the slate and start fresh - but after removing the lookup table and definition, I am unable to remove the entry from the "Automatic Lookup" list.

Error Quoted:

*Error occurred attempting to remove '680-lookup-auto' In handler
'props-lookup': Object
'680-lookup-auto' does not
exist in user=admin, app=search:
props.conf

Checked props.conf and sure enough it's not listed. Need to have it removed as every normal search will return errors on the main page refering to the auto-lookup.

Any help would be appreciated.

Tags (1)
0 Karma

Drainy
Champion

Which props.conf have you checked?
Possible locations for it could be;

SPLUNK_HOME/etc/apps/search/local/
SPLUNK_HOME/etc/users/USERNAME/APP/local/  <- could be the search app here
SPLUNK_HOME/etc/system/local/

A nice quick way to check is to run the following command in the SPLUNK_HOME/bin directory;

Linux - ./splunk cmd btool props list --debug

Windows - splunk cmd btool props list --debug

This will list all the lines from props.conf it has read in and prefix it with the name of the app applying it.

Drainy
Champion

No problem, glad it helped 🙂 Feel free to click on the tick to the left of my answer, it will just mark this as the right answer for anyone with the same problem in the future.

0 Karma

aphextwin
New Member

thanks for that mate! the debug tool helped!
found the reference, removed it, restarted and i was able to remove it from the autolookup list.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...