Splunk Enterprise

Last Line Entry in Lookup Not Appearing in Search

gearmstrong
Path Finder

Hi group,

Recently upgraded to 8.1.0.1 with single 'all-in-one' configuration.  Yesterday I made a new line entry at the bottom of a long-used Lookup csv file and today it seemed to be ignored.  We have a simple search that basically checks for unknown logins (see below)

index=msad
NOT [| inputlookup SIDLookup.csv | fields SID]
| dedup SID

Now, even when I searched with "| inputlookup SIDLookup.csv" the last entry did not show up.  I then edited the file again and added a blank new line after my last entry and ensured 'word wrap' was off.  The lookup file is only a four field lookup with nothing crazy (Name,SID,whenCreated,whenChanged).  Each value is enclosed in Double-quotes and comma-separated with no spaces in between.

Every other entry is working fine... just not the last one.  Trying to figure out where this is breaking down.

Thanks,

Greg

 

Labels (1)
0 Karma
1 Solution

gearmstrong
Path Finder

*** SOLVED *** Colleague of mine discovered that in the last Field Value of the Last Line entry I had sloppily eased up on the <SHIFT> Key and the Double Quote had became a Single Quote.  Things like this can be difficult to spot, working remotely on small screen systems.  Something to keep in mind... and as always it's nice to have a second pair of eyes on your work!

 

Best regards,

Greg

View solution in original post

0 Karma

gearmstrong
Path Finder

*** SOLVED *** Colleague of mine discovered that in the last Field Value of the Last Line entry I had sloppily eased up on the <SHIFT> Key and the Double Quote had became a Single Quote.  Things like this can be difficult to spot, working remotely on small screen systems.  Something to keep in mind... and as always it's nice to have a second pair of eyes on your work!

 

Best regards,

Greg

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...