Splunk Enterprise

/opt/splunk/etc/system/lookups/README Keeps Disappearing

b17gunnr
Path Finder

Hello Friends,

I am consistently receiving alerts that the README file found in the path /opt/splunk/etc/system/lookups/ within my SHC is missing. When hit that directory I can confirm that it is gone, and while I believe it to be a default file, when I take a copy of it from another instance that has no issue, the file is removed after 5 or so minutes. I have confirmed that file owner and group are splunk and while the file is present, I can cat it without issue.

Would anyone have seen this themselves or have any ideas on how to remediate it? Thank you.

Labels (1)
0 Karma
1 Solution

PrewinThomas
Motivator

@b17gunnr 

Could you please check if anyone accidentally put a system app inside the shcluster/apps/ folder? Also, can you see if there are any local scripts or jobs that might be cleaning up or removing files from the lookup folder?

Also anything from splunk _internal logs?

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

View solution in original post

b17gunnr
Path Finder

There is an automation that is supposed to only grab CSV files and move them into another directory. Looks like it needs to be tweaked because it is also grabbing text files. Appreciate the help.

0 Karma

PrewinThomas
Motivator

@b17gunnr 

Could you please check if anyone accidentally put a system app inside the shcluster/apps/ folder? Also, can you see if there are any local scripts or jobs that might be cleaning up or removing files from the lookup folder?

Also anything from splunk _internal logs?

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...