Splunk Enterprise Security

Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'

edwardrose
Contributor

On my Enterprise Security search head I am getting the following errors:

[splk-idx-01.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-01.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
[splk-idx-02.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-02.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
[splk-idx-03.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-03.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.

We added the TA-sepapp12 to the search head and these errors started after that. Previously we had only added the TA-sep addon and we were not seeing all the correct lookups. After we added the TA-sepapp12 to the ES search head we started seeing items fill up in the dashboards that address SEP/Virus/Malware in ES.

So how do I fix the errors now in the ES search area?

thanks
ed

0 Karma
1 Solution

edwardrose
Contributor

Moved the TA-sep to disabled apps.

We had multiple lookup definitions looking at the same file. Both TA-sepapp12 and TA-sep had lookup definitions looking at sep_actions.csv. once we removed TA-sep and consolidated to TA-sepap12 issue was resolved.

View solution in original post

edwardrose
Contributor

Moved the TA-sep to disabled apps.

We had multiple lookup definitions looking at the same file. Both TA-sepapp12 and TA-sep had lookup definitions looking at sep_actions.csv. once we removed TA-sep and consolidated to TA-sepap12 issue was resolved.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...