Splunk Enterprise

/opt/splunk/etc/system/lookups/README Keeps Disappearing

b17gunnr
Explorer

Hello Friends,

I am consistently receiving alerts that the README file found in the path /opt/splunk/etc/system/lookups/ within my SHC is missing. When hit that directory I can confirm that it is gone, and while I believe it to be a default file, when I take a copy of it from another instance that has no issue, the file is removed after 5 or so minutes. I have confirmed that file owner and group are splunk and while the file is present, I can cat it without issue.

Would anyone have seen this themselves or have any ideas on how to remediate it? Thank you.

Labels (1)
0 Karma
1 Solution

PrewinThomas
Motivator

@b17gunnr 

Could you please check if anyone accidentally put a system app inside the shcluster/apps/ folder? Also, can you see if there are any local scripts or jobs that might be cleaning up or removing files from the lookup folder?

Also anything from splunk _internal logs?

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

View solution in original post

b17gunnr
Explorer

There is an automation that is supposed to only grab CSV files and move them into another directory. Looks like it needs to be tweaked because it is also grabbing text files. Appreciate the help.

0 Karma

PrewinThomas
Motivator

@b17gunnr 

Could you please check if anyone accidentally put a system app inside the shcluster/apps/ folder? Also, can you see if there are any local scripts or jobs that might be cleaning up or removing files from the lookup folder?

Also anything from splunk _internal logs?

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...