Splunk Search

Empty Lookup Tables - disable warning banner

apgersplunk
New Member

version 6

I maintain a set of csv files as lookup tables and everything works perfectly fine with one exception. If any of the files contain only a header but no data, the views that reference the collection of lookups pastes a yellow warning banner across the UI stating "Empty csv lookup file (contains only a header) for table ...".

Some of the csv files will occasionally be empty by design (header only) and I am trying to figure out how to disable these warnings. Any ideas?

Tags (3)
0 Karma

apgersplunk
New Member

Thanks for the quick reply and good pointer. I tested the logging levels associated with "lookup" and "csv" related channels with no luck. It seems that the handler would have fixed it. I made the test changes through the GUI while troubleshooting.

0 Karma

MuS
Legend

Hi apgersplunk,

you can either set it in log.cfg or in the Manager - System Settings - System logging and change the setting for one of the lookup channels. Available channels are:

  • LookupOperator
  • LookupTableConfPathMapper
  • LookupTablesHandler

hope this helps ...

cheers, MuS

MuS
Legend

another thought just came up my head...you can disable/modify the message bar in the XML of your views as well ..... but, this is dangerzone, because you can set it to be too strict and you will also NOT receive any other message as well (like license violations)

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...