Splunk Enterprise Security

Splunk Enterprise Security: Correlation search lookup not working, yet -- works in normal search

gopmister
Explorer

I am running a ESS Correlation search in App Context Enterprise Security. I verified the lookup and it exists in the lookup editor with Global permissions and proper definition. Yet when I run the search in ES, I get an error in lookup command. The lookup table 'DisabledUsers' does not exist or is not available.

Yet when I run the same search in Search and Reporting app, it runs normally and returns results just fine. I even tried to go in the lookup and enable permission to ess_admin, ess_user, and ess_analyst, but that did not work. Any suggestions?

0 Karma

gjanders
SplunkTrust
SplunkTrust

The Splunk Enterprise Security application has an imported application list, perhaps the lookup file you are referring to is in an application which the enterprise security app is not currently importing?

Have you tested moving the lookup into the ES app? Or double checking the list of imported apps and see if the relevant app that includes the lookup should be imported...

The command mentioned in the documentation is:

| rest /servicesNS/admin/system/apps/local/SplunkEnterpriseSecuritySuite/import splunk_server=local | fields import

This should list the applications imported...

0 Karma

gopmister
Explorer

I checked and the application under which the lookup resides is not imported into the ES. Maybe that is why I am not able to see it. Anyway I can make the app import into the ES?

0 Karma

gjanders
SplunkTrust
SplunkTrust

Refer to https://docs.splunk.com/Documentation/ES/latest/Install/ImportCustomApps in particular the section "Import add-ons with a different naming convention", that way you can import the required application into ES.

Alternatively, move the lookup into the ES application 🙂

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...