Splunk Enterprise Security

Splunk ES - lookup_expander - assets.csv - not handling IPv6?

OL
Communicator

Hello Splunk ES users 🙂

I'm using the latest Splunk ES (2.4.0) and since the upgrade from 2.0.2, I have the following error:

lookup_expander: Some lines in the input CSV contained bad data (file: /opt/splunk/etc/apps/SA-IdentityManagement/lookups/assets.csv, count: 141)

All 141 errors are coming from the entries which are using IPv6 from the assets.csv. Isn't ES support IPv6?

Regards,
Olivier

1 Solution

LukeMurphey
Champion

Sadly, ES doesn't support IPv6, yet.

View solution in original post

LukeMurphey
Champion

Sadly, ES doesn't support IPv6, yet.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...