Splunk Search

Error: [indexer1] Empty csv lookup file

HeinzWaescher
Motivator

Hi,

I've got a large (170.000 rows) lookupfile that is used in several searches. I've scheduled these searches to run once per day. Sometimes the results are incorrect and the this message appears:

[[indexer1] Empty csv lookup file (contains only a header) for table 'lookup.csv': /opt/splunk/var/run/searchpeers/search-head1-1392875960/apps/App_Name/lookups/lookup.csv

So Splunk tried to create an index out of the lookup, but it failed?

Any ideas how I can fix this error?

BG

Heinz

0 Karma

HeinzWaescher
Motivator

Adjusting the limits.conf did not solve the problem... Searches using the lookup command still fail randomly, so I would still be happy about additional hints.

BR Heinz

0 Karma

hartfoml
Motivator

I am having this same problem. any help would help the community

[MyIndexer1.local.com] Empty csv lookup file (contains only a header) for table 'MyLookupFile': /opt/splunk/var/run/searchpeers/MyIndexer1.local.com-1397750703/apps/search/lookups/MyLookupFile.csv

[MyIndexer2.local.com] Empty csv lookup file (contains only a header) for table 'MyLookupFile': /opt/splunk/var/run/searchpeers/MyIndexer2.local.com-1397750703/apps/search/lookups/MyLookupFile.csv

0 Karma

muralianup
Communicator

Any luck with this ? I am having simialr problem with Qualys KB CSV

0 Karma

HeinzWaescher
Motivator

I tried to change this value in the limits.conf as a first workaround, so that the lookup is not indexed.

[lookup] max_memtable_bytes = 50000000

I'm not sure whether this works. Is it possible to run a search thats shows the folder & size of the .csv (and the index if it exists)?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

That means your lookup file is empty. What is generating the lookup file?

HeinzWaescher
Motivator

It has to be on the search head as well, because sometimes the searchresults are correct. the error seems to appear randomly.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Yes, They only really need to be on the search head.

0 Karma

linu1988
Champion

Shouldn't the look up be placed in search head only?

0 Karma

HeinzWaescher
Motivator

Unfortunately the IRC doesn't work at my side at the moment.

I think we've looked at the file on the indexer.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Where did you look? On indexer1? or on the Search Head? Also - I am on IRC #splunk -efnet if you want to chat directly.

0 Karma

HeinzWaescher
Motivator

But it is not empty, we've opened it and it looks fine.
The lookupfile is created by a splunk search

my search | outputlookup lookup.csv

The lookup file is around 28MB and an index is created as well.

Sometimes it works, sometimes the error appears. It's really strange

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...