Splunk Enterprise

What lookup permission or capability isn't set properly?

adamsmith47
Communicator

We're running Splunk 8.1.7.2. I am an admin. I have created a lookup file (my_lookup.csv), and lookup definition (my_lookup) referencing that file, in an app (my_app). Both the lookup file and definition have permission set to "All Apps (system)" and "Everyone Read", write is for admin only.

When I run the following searches I see contents of the lookup files as expected:
| inputlookup my_lookup.csv
OR
| inputlookup my_lookup

However, when my users attempts to run the search above, they get the following errors:
-"The lookup table 'my_lookup.csv' requires a .csv or KV store lookup definition."
-"The lookup table 'my_lookup' is invalid."

I don't understand how this could be. Also, it's worth pointing out the user used to be able to get results.

What permission or capability isn't set properly?

Any help is greatly appreciated. Thanks.

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...