Splunk Enterprise Security
Highlighted

Splunk ES - lookup_expander - assets.csv - not handling IPv6?

Communicator

Hello Splunk ES users 🙂

I'm using the latest Splunk ES (2.4.0) and since the upgrade from 2.0.2, I have the following error:

lookup_expander: Some lines in the input CSV contained bad data (file: /opt/splunk/etc/apps/SA-IdentityManagement/lookups/assets.csv, count: 141)

All 141 errors are coming from the entries which are using IPv6 from the assets.csv. Isn't ES support IPv6?

Regards,
Olivier

Highlighted

Re: Splunk ES - lookup_expander - assets.csv - not handling IPv6?

Champion

Sadly, ES doesn't support IPv6, yet.

View solution in original post