Splunk Enterprise Security

ESS error with conf 'oracle' lookup table 'oracle_action_lookup'

xuanyun
Path Finder

Dear expert:

When I installed ESS, I found a ERROR on the top of splunk's web.

Error 'Could not find all of the specified destination fields in the lookup table.' for conf 'oracle' and lookup table 'oracle_action_lookup'.

I didn't do any change.
How can I solve it?

0 Karma
1 Solution

LukeMurphey
Champion

'oracle_action_lookup' is part of TA-oracle and it is used for converting the action field provided from Oracle to a Common Information Model equivalent.

I cannot figure out why you would see this error because the props.conf entry only looks up one field so is should work:

[oracle]
...
LOOKUP-action_for_oracle_auth = oracle_action_lookup ACTION OUTPUTNEW action

I recommend opening a support case and providing a diag. Support should be able to identify the problem fairly quickly with a diag.

View solution in original post

0 Karma

LukeMurphey
Champion

'oracle_action_lookup' is part of TA-oracle and it is used for converting the action field provided from Oracle to a Common Information Model equivalent.

I cannot figure out why you would see this error because the props.conf entry only looks up one field so is should work:

[oracle]
...
LOOKUP-action_for_oracle_auth = oracle_action_lookup ACTION OUTPUTNEW action

I recommend opening a support case and providing a diag. Support should be able to identify the problem fairly quickly with a diag.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...