Splunk Enterprise Security

Found Error : the indexers could not load lookup

nareerat_pr
Explorer

I've created a search-driven lookup on Splunk ES, then I try to create an automatic lookups with the new lookup file.

I found error messages as follow:

[indexer1] Could not load lookup=LOOKUP-lookup_definitions_name

[indexer2] Could not load lookup=LOOKUP-lookup_definitions_name

[indexer3] Could not load lookup=LOOKUP-lookup_definitions_name

...

How can I resolve this issue?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
The automatic lookup should reference a lookup definition which invokes your lookup file. Do you have all three pieces in place?
---
If this reply helps you, Karma would be appreciated.
0 Karma

nareerat_pr
Explorer

Yes, I have all three pieces.

0 Karma
Get Updates on the Splunk Community!

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...