Splunk Enterprise Security

How to access data from a Lookup table in another app to a custom dashboard in ES?

richkappler
Path Finder

Trying to access data from a lookup table in another app (TA_recordedfuture-cyber) to a custom dashboard we've created in our ES instance. "lookup table is invalid."

Have verified that lookup is available to all apps and has global permissions.

Lookups from that app are available in all other apps on the search head except ES.

Do I need to Configure > Data Enrichment > Lists and Lookups > Add Lookup to make this available?
If I do, does that affect the availability of that lookup table in it's parent app or other apps?

0 Karma
1 Solution

adonio
Ultra Champion

did you define the lookup?
did you give the right permissions to the lookup definition?
http://docs.splunk.com/Documentation/Splunk/7.1.2/Knowledge/Usefieldlookupstoaddinformationtoyoureve...

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...