Splunk Enterprise

Could not load lookup=LOOKUP-record_type

xenomorph
Loves-to-Learn Lots

 WE updated the Sysmon add-on from 3.x to 4.0.1 (latest) on a search head cluster. After, we're getting errors about how the node we're on and the indexers can't load a lookup

(Could not load lookup=LOOKUP-record_type).

Labels (1)
0 Karma

xenomorph
Loves-to-Learn Lots

many thanks to Ryan McGinn

0 Karma

xenomorph
Loves-to-Learn Lots

In Splunk_TA_microsoft_sysmon\default\app.conf or Splunk_TA_microsoft_sysmon\local\app.conf add the following then deploy the SHC bundle 

[shclustering]
deployer_lookups_push_mode = always_overwrite

In the app.conf seems the best way for the sysmon TA

0 Karma

xenomorph
Loves-to-Learn Lots

the -preserve-lookups true option when we did the SHC bundle push and the add-on's 3.x version of the lookup had a different field name (record_type ) vs the version in 4.x which is record_type_id.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...