Splunk Search

Can you help us with the following Lookup table error: "ERROR LookupOperator - Error in 'lookup' command"

evertonpsp
New Member

Can anyone help me with error below?
...

11-06-2018 16:34:19.371 WARN  LookupOperator - Failed to find static lookup file: mmcb_ad_accounts.csv
**11-06-2018 16:34:19.371 ERROR LookupOperator - Error in 'lookup' command: Lookups: The lookup table 'mmcb_ad_accounts' does not exist or is not available.**
11-06-2018 16:34:19.371 ERROR SearchPhaseGenerator - Fallback to two phase search failed:Error in 'lookup' command: Lookups: The lookup table 'mmcb_ad_accounts' does not exist or is not available.
11-06-2018 16:34:19.372 ERROR SearchOrchestrator - Error in 'lookup' command: Lookups: The lookup table 'mmcb_ad_accounts' does not exist or is not available.
11-06-2018 16:34:19.372 INFO  SearchStatusEnforcer - Enforcing disk quota = 104857600
11-06-2018 16:34:19.374 INFO  UserManager - Unwound user context: opuser -> NULL
11-06-2018 16:34:19.376 INFO  UserManager - Unwound user context: opuser -> NULL
11-06-2018 16:34:19.376 ERROR dispatchRunner - RunDispatch::runDispatchThread threw error: Error in 'lookup' command: Lookups: The lookup table 'mmcb_ad_accounts' does not exist or is not 
0 Karma

marycordova
SplunkTrust
SplunkTrust

How is the lookup file mmcb_ad_accounts.csv created and where is it stored? Also...if this is on linux what are the file permissions and what are the permissions on the file in the Splunk UI as well?

@marycordova
0 Karma

evertonpsp
New Member

Hi Mary,
I feel happy to have your help. Thanks in advanced!

The file mmcb_ad_accounts.csv is create by Splunk job and update every day at 00h. The OS the server where the file is store is Linux. Bellow the file permissions:

-rw------- 1 root root 101669 Nov 7 00:01 mmcb_ad_accounts.csv

In Splunk GUI, the file settings are as follows:

Object should appear in:
All apps

Permissions:
Read: Everyone Roles
Write: admin and power Roles

File - Splunk permission

Additional Notes:

The problem happens with users belonging to Role user_service_desk.
For users belonging to Role admin, the problem does not occur.

If I edit the Role user_service_desk and include in the Inheritance field the Role admin, the problem no longer happens for Role users user_service_desk

Best regards!

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...