Splunk Search

App ServiceNow (SNOW) - Lookup File Errors for ServiceNow App.

dkolekar_splunk
Splunk Employee
Splunk Employee

The lookup table 'xxxxx_xxxx_xxxx' does not exist. It is referenced by configuration 'snow:change_request'.

Add-on version: 3.1.2

Description:
Errors occur on lookup files when trying to use the Splunk app for ServiceNow.

How to identify it:
1. Customer will receive the next errors:
5 errors occurred while the search was executing. Therefore, search results might be incomplete.

[hostname.com] Info.csv being bloated by "lookup" log messages . Will not log additional errors. Refer search.log
[hostname.com] The lookup table 'change_state_lookup' does not exist. It is referenced by configuration 'snow:change_request'.
[hostname.com] The lookup table 'change_state_lookup' does not exist. It is referenced by configuration 'snow:change_task'.
[hostname.com] The lookup table 'cmdb_ci_list_lookup' does not exist. It is referenced by configuration 'snow:change_request'.
[hostname.com] The lookup table 'cmdb_ci_list_lookup' does not exist. It is
2. Lookup files from Splunk app for SeviceNow creating lookup files over 1GB in size

Tags (1)
0 Karma
1 Solution

dkolekar_splunk
Splunk Employee
Splunk Employee

In order to resolve this issue, we need to reduce the bundle size.

Performance issue caused by large bundle replication
The two largest lookups, cmdb_ci_list_lookup.csv and cmdb_rel_ci.csv, cause performance issues with the ServiceNow app 4.0.2 because they are excessively large. To resolve this performance issue, upgrade to Splunk App for Servicenow 4.0.3, which no longer uses these two lookups, then disable the following two saved searches:

ServiceNow CMDB CI Relation
ServiceNow CMDB CI List

Related Links

Lookups for the Splunk Add-on for ServiceNow
http://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Lookups

Remove deleted configuration items from the configuration management database lookups
http://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Troubleshooting#Remove_deleted_confi...

View solution in original post

Roy_9
Motivator

Hi @dkolekar_splunk 
Can you help me with Snow incident geographical dashboard, i have already enabled incident table and location table inputs using the add-on, but i am unable to correlate this and populate the dashboard. there is no common field between two tables like latitide, longitude or location? Did you ever faced this issue?

Please help me out.

 

Thanks

0 Karma

dkolekar_splunk
Splunk Employee
Splunk Employee

In order to resolve this issue, we need to reduce the bundle size.

Performance issue caused by large bundle replication
The two largest lookups, cmdb_ci_list_lookup.csv and cmdb_rel_ci.csv, cause performance issues with the ServiceNow app 4.0.2 because they are excessively large. To resolve this performance issue, upgrade to Splunk App for Servicenow 4.0.3, which no longer uses these two lookups, then disable the following two saved searches:

ServiceNow CMDB CI Relation
ServiceNow CMDB CI List

Related Links

Lookups for the Splunk Add-on for ServiceNow
http://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Lookups

Remove deleted configuration items from the configuration management database lookups
http://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Troubleshooting#Remove_deleted_confi...

Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...