Splunk Enterprise

/opt/splunk/etc/system/lookups/README Keeps Disappearing

b17gunnr
Explorer

Hello Friends,

I am consistently receiving alerts that the README file found in the path /opt/splunk/etc/system/lookups/ within my SHC is missing. When hit that directory I can confirm that it is gone, and while I believe it to be a default file, when I take a copy of it from another instance that has no issue, the file is removed after 5 or so minutes. I have confirmed that file owner and group are splunk and while the file is present, I can cat it without issue.

Would anyone have seen this themselves or have any ideas on how to remediate it? Thank you.

Labels (1)
0 Karma
1 Solution

PrewinThomas
Motivator

@b17gunnr 

Could you please check if anyone accidentally put a system app inside the shcluster/apps/ folder? Also, can you see if there are any local scripts or jobs that might be cleaning up or removing files from the lookup folder?

Also anything from splunk _internal logs?

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

View solution in original post

b17gunnr
Explorer

There is an automation that is supposed to only grab CSV files and move them into another directory. Looks like it needs to be tweaked because it is also grabbing text files. Appreciate the help.

0 Karma

PrewinThomas
Motivator

@b17gunnr 

Could you please check if anyone accidentally put a system app inside the shcluster/apps/ folder? Also, can you see if there are any local scripts or jobs that might be cleaning up or removing files from the lookup folder?

Also anything from splunk _internal logs?

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...