Splunk Search

Distributed Search and Lookups

ruisantos
Path Finder

Hi,

I'm getting an error on my Search Head when browsing for content related to some LOOKUP directives I have in my apps.

The LOOKUP directives were copied from one of the search peers were they are working.

Currently my problems are: - I'm getting an error stating that this lookup does not exist on one of the search peers (true, because that search peer does not required them) - the LOOKUP directives are not working on the search head.

Any ideas on how this can be solved?

0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

Splunk should automatically move lookup related files to the search peers from the search head. Is this a script-based lookup? If so, there are some intricacies in getting these to work in distributed, since they may land in a different-than-expected directory.

Could you share your configuration and the general mechanism of operation for your lookup?

0 Karma

gfriedmann
Communicator

What are the intricacies for a script based lookup in a distributed environment? For example, dnslookup.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...