On my Enterprise Security search head I am getting the following errors:
[splk-idx-01.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-01.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
[splk-idx-02.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-02.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
[splk-idx-03.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-03.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
We added the TA-sepapp12 to the search head and these errors started after that. Previously we had only added the TA-sep addon and we were not seeing all the correct lookups. After we added the TA-sepapp12 to the ES search head we started seeing items fill up in the dashboards that address SEP/Virus/Malware in ES.
So how do I fix the errors now in the ES search area?
thanks
ed
Moved the TA-sep to disabled apps.
We had multiple lookup definitions looking at the same file. Both TA-sepapp12 and TA-sep had lookup definitions looking at sep_actions.csv. once we removed TA-sep and consolidated to TA-sepap12 issue was resolved.
Moved the TA-sep to disabled apps.
We had multiple lookup definitions looking at the same file. Both TA-sepapp12 and TA-sep had lookup definitions looking at sep_actions.csv. once we removed TA-sep and consolidated to TA-sepap12 issue was resolved.