Splunk Enterprise Security

ESS error with conf 'oracle' lookup table 'oracle_action_lookup'

xuanyun
Path Finder

Dear expert:

When I installed ESS, I found a ERROR on the top of splunk's web.

Error 'Could not find all of the specified destination fields in the lookup table.' for conf 'oracle' and lookup table 'oracle_action_lookup'.

I didn't do any change.
How can I solve it?

0 Karma
1 Solution

LukeMurphey
Champion

'oracle_action_lookup' is part of TA-oracle and it is used for converting the action field provided from Oracle to a Common Information Model equivalent.

I cannot figure out why you would see this error because the props.conf entry only looks up one field so is should work:

[oracle]
...
LOOKUP-action_for_oracle_auth = oracle_action_lookup ACTION OUTPUTNEW action

I recommend opening a support case and providing a diag. Support should be able to identify the problem fairly quickly with a diag.

View solution in original post

0 Karma

LukeMurphey
Champion

'oracle_action_lookup' is part of TA-oracle and it is used for converting the action field provided from Oracle to a Common Information Model equivalent.

I cannot figure out why you would see this error because the props.conf entry only looks up one field so is should work:

[oracle]
...
LOOKUP-action_for_oracle_auth = oracle_action_lookup ACTION OUTPUTNEW action

I recommend opening a support case and providing a diag. Support should be able to identify the problem fairly quickly with a diag.

0 Karma
Get Updates on the Splunk Community!

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...

The Visibility Gap: Hybrid Networks and IT Services

The most forward thinking enterprises among us see their network as much more than infrastructure – it's their ...

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...