Splunk Enterprise Security

Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'

edwardrose
Contributor

On my Enterprise Security search head I am getting the following errors:

[splk-idx-01.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-01.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
[splk-idx-02.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-02.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
[splk-idx-03.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-03.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.

We added the TA-sepapp12 to the search head and these errors started after that. Previously we had only added the TA-sep addon and we were not seeing all the correct lookups. After we added the TA-sepapp12 to the ES search head we started seeing items fill up in the dashboards that address SEP/Virus/Malware in ES.

So how do I fix the errors now in the ES search area?

thanks
ed

0 Karma
1 Solution

edwardrose
Contributor

Moved the TA-sep to disabled apps.

We had multiple lookup definitions looking at the same file. Both TA-sepapp12 and TA-sep had lookup definitions looking at sep_actions.csv. once we removed TA-sep and consolidated to TA-sepap12 issue was resolved.

View solution in original post

edwardrose
Contributor

Moved the TA-sep to disabled apps.

We had multiple lookup definitions looking at the same file. Both TA-sepapp12 and TA-sep had lookup definitions looking at sep_actions.csv. once we removed TA-sep and consolidated to TA-sepap12 issue was resolved.

Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...