Splunk Search

Could not load lookup=LOOKUP-browser ???

Jarohnimo
Builder

Hello All,

I just upgraded to the latest version of Splunk 7.2.5 and now when I search anything i recieve errors stating "Could not load lookup=LOOKUP-Browser"

I'm not sure what that is, I never used a "Lookup Browser" table or anything of the sort prior to this update so i'm not sure where the message is coming from. Can someone please point me in the direction of how to get rid of/ mute this message?

Also If you have any input on what LOOKUP-Browser is, i'd appreciate it! thanks!

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

It looks like you had Lookup definition, Lookup file or Automatic Lookup with name Browser in your splunk configuration and now splunk is not able to find that lookup file but in configuration file it is still pointing to non-existing lookup or lookup file or lookup definition permission has been changed and due to that automatic lookup is not able to find that lookup.

If you have CLI access then check lookup props and transforms configuration using btool

View solution in original post

harsmarvania57
Ultra Champion

Hi,

It looks like you had Lookup definition, Lookup file or Automatic Lookup with name Browser in your splunk configuration and now splunk is not able to find that lookup file but in configuration file it is still pointing to non-existing lookup or lookup file or lookup definition permission has been changed and due to that automatic lookup is not able to find that lookup.

If you have CLI access then check lookup props and transforms configuration using btool

rajasha
Explorer

Hi @harsmarvania57 @Jarohnimo @nickhills  I'm facing same problem but with multiple lookup error. Where I'm using cloud enterprise architecture then how could I able to check the same? Do I need to check in somewhere else?

0 Karma

harsmarvania57
Ultra Champion

Hi,

If you are using Splunk Cloud then you don't have CLI access on Splunk search heads, I guess you need to raise case with support.

Thanks,

Harshil

0 Karma

Jarohnimo
Builder

Thanks harsmarvania57, It ended up being a very old entry under my search/ props conf file that had this entry. Thanks! (I'm trying to mark your response as the answer).

0 Karma

harsmarvania57
Ultra Champion

That's great that you found the issue. I have converted my comment to answer so that you can accept it.

0 Karma

nickhills
Ultra Champion

Copy/Paste command to find the culprit:

/opt/splunk/bin/splunk btool props list --debug |grep LOOKUP-Browser

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...