Splunk Enterprise

Last Line Entry in Lookup Not Appearing in Search

gearmstrong
Path Finder

Hi group,

Recently upgraded to 8.1.0.1 with single 'all-in-one' configuration.  Yesterday I made a new line entry at the bottom of a long-used Lookup csv file and today it seemed to be ignored.  We have a simple search that basically checks for unknown logins (see below)

index=msad
NOT [| inputlookup SIDLookup.csv | fields SID]
| dedup SID

Now, even when I searched with "| inputlookup SIDLookup.csv" the last entry did not show up.  I then edited the file again and added a blank new line after my last entry and ensured 'word wrap' was off.  The lookup file is only a four field lookup with nothing crazy (Name,SID,whenCreated,whenChanged).  Each value is enclosed in Double-quotes and comma-separated with no spaces in between.

Every other entry is working fine... just not the last one.  Trying to figure out where this is breaking down.

Thanks,

Greg

 

Labels (1)
0 Karma
1 Solution

gearmstrong
Path Finder

*** SOLVED *** Colleague of mine discovered that in the last Field Value of the Last Line entry I had sloppily eased up on the <SHIFT> Key and the Double Quote had became a Single Quote.  Things like this can be difficult to spot, working remotely on small screen systems.  Something to keep in mind... and as always it's nice to have a second pair of eyes on your work!

 

Best regards,

Greg

View solution in original post

0 Karma

gearmstrong
Path Finder

*** SOLVED *** Colleague of mine discovered that in the last Field Value of the Last Line entry I had sloppily eased up on the <SHIFT> Key and the Double Quote had became a Single Quote.  Things like this can be difficult to spot, working remotely on small screen systems.  Something to keep in mind... and as always it's nice to have a second pair of eyes on your work!

 

Best regards,

Greg

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...