Splunk Enterprise Security

Found Error : the indexers could not load lookup

nareerat_pr
Explorer

I've created a search-driven lookup on Splunk ES, then I try to create an automatic lookups with the new lookup file.

I found error messages as follow:

[indexer1] Could not load lookup=LOOKUP-lookup_definitions_name

[indexer2] Could not load lookup=LOOKUP-lookup_definitions_name

[indexer3] Could not load lookup=LOOKUP-lookup_definitions_name

...

How can I resolve this issue?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
The automatic lookup should reference a lookup definition which invokes your lookup file. Do you have all three pieces in place?
---
If this reply helps you, Karma would be appreciated.
0 Karma

nareerat_pr
Explorer

Yes, I have all three pieces.

0 Karma
Get Updates on the Splunk Community!

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...