I wanted to update splunk_security_essentials app (3.2.2 to 3.3.2) : after I did the restart, I have this error under all searches :
"Could not load lookup=LOOKUP-splunk_security_essentials"
I found out that there is an automatic lookup set like that :
I did a btool command and see this :
opt/splunk/bin/splunk btool props list --debug |grep LOOKUP-splunk_security_essentials
/opt/splunk/etc/apps/Splunk_Security_Essentials/default/props.conf LOOKUP-splunk_security_essentials = sse_content_exported_lookup search_title AS search_name OUTPUTNEW
What can I do to remove this error ?
Thanks for your help!