Splunk Search

Error: Cannot expand lookup field due to a reference cycle in the lookup configuration

anapp
Explorer

OK, this is odd

Search: 

index=myindex

Works and returns a field "Name", happily listing all values of Name as expected

However any search on the name field e.g.

index=myindex Name=Fred

returns the error:

Cannot expand lookup field 'Name' due to a reference cycle in the lookup configuration. Check search.log for details and update the lookup configuration to remove the reference cycle.

Unfortunately I have no idea what to search for in the search log 

Splunk support have only pointed me to this discussion and told me to re-save a specific cisco lookup:

https://community.splunk.com/t5/Splunk-Cloud-Platform/Cannot-expand-lookup-field-due-to-a-reference-...

and it isn't that as we don't have that cisco lookup table 🙂

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

The broader issue referred to in that linked page you posted, is not specifically about Cisco, but about the resolution of field evaluations. Your Name field is being extracted by Splunk at search time and somewhere in Splunk's process of finding out what Name field should be, it is coming across the reference cycle issue described.

As ray says in that post, they recently upgraded the message from INFO to WARN. 

Have a look at the job inspector search log and look for 'cycle' as described in the post and see if that gives any clues as to why there is that issue occurring on your Name field.

Do you have any Cisco TA installed? As you are on Splunk Cloud, I would suggest you raise a ticket with Splunk asking THEM to run the btool command for you to see if they can identify the problem in your config.

 

View solution in original post

anapp
Explorer

Thanks 

Tracked down the lookup file but no obvious issue - I shall "nudge" splunks support as I was asking here due to their sluggishness 🙂

0 Karma

bowesmana
SplunkTrust
SplunkTrust

The broader issue referred to in that linked page you posted, is not specifically about Cisco, but about the resolution of field evaluations. Your Name field is being extracted by Splunk at search time and somewhere in Splunk's process of finding out what Name field should be, it is coming across the reference cycle issue described.

As ray says in that post, they recently upgraded the message from INFO to WARN. 

Have a look at the job inspector search log and look for 'cycle' as described in the post and see if that gives any clues as to why there is that issue occurring on your Name field.

Do you have any Cisco TA installed? As you are on Splunk Cloud, I would suggest you raise a ticket with Splunk asking THEM to run the btool command for you to see if they can identify the problem in your config.

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...