Splunk Search

Clustered search heads broke lookup tables where do I reupload the lookups?

rtalcik
Path Finder

Hi All,

so i clustered my search heads and added them to my index cluster. However it broke all my lookup tables. I took a backup of /opt/splunk/etc before I did this on the search head with all the lookups.

I guess my question is, is this as simple as just pasting the old lookups into the lookup /system/lookups/

IF SO, where do i do this on? the mgmt_uri? or the captain search head?

if not? can you paste a doc to follow?

0 Karma

codebuilder
Influencer

You'll need use the deployer to distribute your lookups if you want them to replicate across the SHC.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...