Splunk Enterprise Security

Search error: that store merged asset and identity data in Splunk Enterprise Security

SplunkExplorer
Contributor

Hi Splunkers, we have a SH with Splunk Enterprise Security installed on it. It is a standalone instance that query some indexers clusters. We are going on about configure it and we loaded some .csv file for Asset and identity management.

Once ewe uploaded those files, when we ran a search we got this situation: the search is executed, but erros about inability to load lookups that store merged asset and identity data in Splunk Enterprise Security are collected. Error syntax is the following:

 

[<indexers listed here>] Could not load lookup=LOOKUP-zu-asset_lookup_by_str-_risk_system
[<indexers listed here>] Could not load lookup=LOOKUP-zu-asset_lookup_by_str-dest
[<indexers listed here>] Could not load lookup=LOOKUP-zu-asset_lookup_by_str-dvc
[<indexers listed here>] Could not load lookup=LOOKUP-zu-asset_lookup_by_str-src
[<indexers listed here>] Could not load lookup=LOOKUP-zv-asset_lookup_by_cidr-_risk_system
[<indexers listed here>] Could not load lookup=LOOKUP-zv-asset_lookup_by_cidr-dest
[<indexers listed here>] Could not load lookup=LOOKUP-zv-asset_lookup_by_cidr-dvc
[<indexers listed here>] Could not load lookup=LOOKUP-zv-asset_lookup_by_cidr-src

 

First think I thought: ok, this is probably a permission issue. BTW, even when I execute the search with admin user that loaded .csv in assent and identity inventory, I got the same error. 
I can add that we modified some OOT DM, to add some fields needed by our SOC.

What could be the root cause?

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...