Splunk Enterprise Security

Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'

edwardrose
Contributor

On my Enterprise Security search head I am getting the following errors:

[splk-idx-01.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-01.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
[splk-idx-02.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-02.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
[splk-idx-03.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-03.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.

We added the TA-sepapp12 to the search head and these errors started after that. Previously we had only added the TA-sep addon and we were not seeing all the correct lookups. After we added the TA-sepapp12 to the ES search head we started seeing items fill up in the dashboards that address SEP/Virus/Malware in ES.

So how do I fix the errors now in the ES search area?

thanks
ed

0 Karma
1 Solution

edwardrose
Contributor

Moved the TA-sep to disabled apps.

We had multiple lookup definitions looking at the same file. Both TA-sepapp12 and TA-sep had lookup definitions looking at sep_actions.csv. once we removed TA-sep and consolidated to TA-sepap12 issue was resolved.

View solution in original post

edwardrose
Contributor

Moved the TA-sep to disabled apps.

We had multiple lookup definitions looking at the same file. Both TA-sepapp12 and TA-sep had lookup definitions looking at sep_actions.csv. once we removed TA-sep and consolidated to TA-sepap12 issue was resolved.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...