Splunk Enterprise Security

One lookup different error

Nawab
Communicator

I have a lookuop that have domain names, I am already using this lookup in a search and its working fine, now I am trying to construct a new search based on same lookup and I get below error.

 

  • [indexer1,indexer2,indexer3,indexer4] The lookup table 'lookup.csv' does not exist or is not available.

the lookup is configured to run for all apps and roles.

both searches are running on ES. 1 has error and other doesnt why?

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

It sounds like your lookup has not been replicated to the lookups. What does your architecture look like? 

Try adding local=true to your lookup command, does it work then? That might help us work out what the issue might be.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...