Splunk Enterprise

/opt/splunk/etc/system/lookups/README Keeps Disappearing

b17gunnr
Explorer

Hello Friends,

I am consistently receiving alerts that the README file found in the path /opt/splunk/etc/system/lookups/ within my SHC is missing. When hit that directory I can confirm that it is gone, and while I believe it to be a default file, when I take a copy of it from another instance that has no issue, the file is removed after 5 or so minutes. I have confirmed that file owner and group are splunk and while the file is present, I can cat it without issue.

Would anyone have seen this themselves or have any ideas on how to remediate it? Thank you.

Labels (1)
0 Karma
1 Solution

PrewinThomas
Motivator

@b17gunnr 

Could you please check if anyone accidentally put a system app inside the shcluster/apps/ folder? Also, can you see if there are any local scripts or jobs that might be cleaning up or removing files from the lookup folder?

Also anything from splunk _internal logs?

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

View solution in original post

b17gunnr
Explorer

There is an automation that is supposed to only grab CSV files and move them into another directory. Looks like it needs to be tweaked because it is also grabbing text files. Appreciate the help.

0 Karma

PrewinThomas
Motivator

@b17gunnr 

Could you please check if anyone accidentally put a system app inside the shcluster/apps/ folder? Also, can you see if there are any local scripts or jobs that might be cleaning up or removing files from the lookup folder?

Also anything from splunk _internal logs?

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...