Splunk Enterprise

What lookup permission or capability isn't set properly?

adamsmith47
Communicator

We're running Splunk 8.1.7.2. I am an admin. I have created a lookup file (my_lookup.csv), and lookup definition (my_lookup) referencing that file, in an app (my_app). Both the lookup file and definition have permission set to "All Apps (system)" and "Everyone Read", write is for admin only.

When I run the following searches I see contents of the lookup files as expected:
| inputlookup my_lookup.csv
OR
| inputlookup my_lookup

However, when my users attempts to run the search above, they get the following errors:
-"The lookup table 'my_lookup.csv' requires a .csv or KV store lookup definition."
-"The lookup table 'my_lookup' is invalid."

I don't understand how this could be. Also, it's worth pointing out the user used to be able to get results.

What permission or capability isn't set properly?

Any help is greatly appreciated. Thanks.

Labels (3)
Tags (2)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...