Splunk Enterprise

Last Line Entry in Lookup Not Appearing in Search

gearmstrong
Path Finder

Hi group,

Recently upgraded to 8.1.0.1 with single 'all-in-one' configuration.  Yesterday I made a new line entry at the bottom of a long-used Lookup csv file and today it seemed to be ignored.  We have a simple search that basically checks for unknown logins (see below)

index=msad
NOT [| inputlookup SIDLookup.csv | fields SID]
| dedup SID

Now, even when I searched with "| inputlookup SIDLookup.csv" the last entry did not show up.  I then edited the file again and added a blank new line after my last entry and ensured 'word wrap' was off.  The lookup file is only a four field lookup with nothing crazy (Name,SID,whenCreated,whenChanged).  Each value is enclosed in Double-quotes and comma-separated with no spaces in between.

Every other entry is working fine... just not the last one.  Trying to figure out where this is breaking down.

Thanks,

Greg

 

Labels (1)
0 Karma
1 Solution

gearmstrong
Path Finder

*** SOLVED *** Colleague of mine discovered that in the last Field Value of the Last Line entry I had sloppily eased up on the <SHIFT> Key and the Double Quote had became a Single Quote.  Things like this can be difficult to spot, working remotely on small screen systems.  Something to keep in mind... and as always it's nice to have a second pair of eyes on your work!

 

Best regards,

Greg

View solution in original post

0 Karma

gearmstrong
Path Finder

*** SOLVED *** Colleague of mine discovered that in the last Field Value of the Last Line entry I had sloppily eased up on the <SHIFT> Key and the Double Quote had became a Single Quote.  Things like this can be difficult to spot, working remotely on small screen systems.  Something to keep in mind... and as always it's nice to have a second pair of eyes on your work!

 

Best regards,

Greg

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...