Hi,
I've got a large (170.000 rows) lookupfile that is used in several searches. I've scheduled these searches to run once per day. Sometimes the results are incorrect and the this message appears:
[[indexer1] Empty csv lookup file (contains only a header) for table 'lookup.csv': /opt/splunk/var/run/searchpeers/search-head1-1392875960/apps/App_Name/lookups/lookup.csv
So Splunk tried to create an index out of the lookup, but it failed?
Any ideas how I can fix this error?
BG
Heinz
Adjusting the limits.conf did not solve the problem... Searches using the lookup command still fail randomly, so I would still be happy about additional hints.
BR Heinz
I am having this same problem. any help would help the community
[MyIndexer1.local.com] Empty csv lookup file (contains only a header) for table 'MyLookupFile': /opt/splunk/var/run/searchpeers/MyIndexer1.local.com-1397750703/apps/search/lookups/MyLookupFile.csv
[MyIndexer2.local.com] Empty csv lookup file (contains only a header) for table 'MyLookupFile': /opt/splunk/var/run/searchpeers/MyIndexer2.local.com-1397750703/apps/search/lookups/MyLookupFile.csv
Any luck with this ? I am having simialr problem with Qualys KB CSV
I tried to change this value in the limits.conf as a first workaround, so that the lookup is not indexed.
[lookup] max_memtable_bytes = 50000000
I'm not sure whether this works. Is it possible to run a search thats shows the folder & size of the .csv (and the index if it exists)?
That means your lookup file is empty. What is generating the lookup file?
It has to be on the search head as well, because sometimes the searchresults are correct. the error seems to appear randomly.
Yes, They only really need to be on the search head.
Shouldn't the look up be placed in search head only?
Unfortunately the IRC doesn't work at my side at the moment.
I think we've looked at the file on the indexer.
Where did you look? On indexer1? or on the Search Head? Also - I am on IRC #splunk -efnet if you want to chat directly.
But it is not empty, we've opened it and it looks fine.
The lookupfile is created by a splunk search
my search | outputlookup lookup.csv
The lookup file is around 28MB and an index is created as well.
Sometimes it works, sometimes the error appears. It's really strange