Splunk Enterprise Security

How to find a Missing Lookup

walsborn
Path Finder

I am new to the Splunk admin role and am having troubles with some errors. When a search is conducting I can see errors coming from all indexers. Starting with [indexer] Could not load lookup=LOOKUP-known_malicious_domains. This is in ES, and I've reviewed splunkd log, var run log, and cannot find additional information on where to look for this lookup. I have tried to manually add this lookup in search with no avail. I have made lookup tables in the search-heads with this filename in etc/apps/search/lookups/known_malicious_domains but that does not seem to help. Anyone else ran into this before?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The lookup file may indeed be missing, but you must add it in the right place. The search app is not the right place.
Go to Settings->Lookups->Lookup Definitions and look for the reported lookup. There you will see the name of the lookup file being used and the app which defines it. Create a replace lookup file by the same name in that app and the error should go away.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The lookup file may indeed be missing, but you must add it in the right place. The search app is not the right place.
Go to Settings->Lookups->Lookup Definitions and look for the reported lookup. There you will see the name of the lookup file being used and the app which defines it. Create a replace lookup file by the same name in that app and the error should go away.

---
If this reply helps you, Karma would be appreciated.
0 Karma

walsborn
Path Finder

Worked! Thanks Rich!

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...