Splunk Dev

Unable to delete automatic lookup

aphextwin
New Member

Hi Folks

I've created a new lookup for Windows event 680 and applied it successfully. This morning, due to some other admin's actions the look up stopped working and troubleshooting it didnt bear any fruit.

I've decided to clear the slate and start fresh - but after removing the lookup table and definition, I am unable to remove the entry from the "Automatic Lookup" list.

Error Quoted:

*Error occurred attempting to remove '680-lookup-auto' In handler
'props-lookup': Object
'680-lookup-auto' does not
exist in user=admin, app=search:
props.conf

Checked props.conf and sure enough it's not listed. Need to have it removed as every normal search will return errors on the main page refering to the auto-lookup.

Any help would be appreciated.

Tags (1)
0 Karma

Drainy
Champion

Which props.conf have you checked?
Possible locations for it could be;

SPLUNK_HOME/etc/apps/search/local/
SPLUNK_HOME/etc/users/USERNAME/APP/local/  <- could be the search app here
SPLUNK_HOME/etc/system/local/

A nice quick way to check is to run the following command in the SPLUNK_HOME/bin directory;

Linux - ./splunk cmd btool props list --debug

Windows - splunk cmd btool props list --debug

This will list all the lines from props.conf it has read in and prefix it with the name of the app applying it.

Drainy
Champion

No problem, glad it helped 🙂 Feel free to click on the tick to the left of my answer, it will just mark this as the right answer for anyone with the same problem in the future.

0 Karma

aphextwin
New Member

thanks for that mate! the debug tool helped!
found the reference, removed it, restarted and i was able to remove it from the autolookup list.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...