Splunk Search

Error: [indexer1] Empty csv lookup file

Motivator

Hi,

I've got a large (170.000 rows) lookupfile that is used in several searches. I've scheduled these searches to run once per day. Sometimes the results are incorrect and the this message appears:

[[indexer1] Empty csv lookup file (contains only a header) for table 'lookup.csv': /opt/splunk/var/run/searchpeers/search-head1-1392875960/apps/App_Name/lookups/lookup.csv

So Splunk tried to create an index out of the lookup, but it failed?

Any ideas how I can fix this error?

BG

Heinz

0 Karma

Motivator

Adjusting the limits.conf did not solve the problem... Searches using the lookup command still fail randomly, so I would still be happy about additional hints.

BR Heinz

0 Karma

Motivator

I am having this same problem. any help would help the community

[MyIndexer1.local.com] Empty csv lookup file (contains only a header) for table 'MyLookupFile': /opt/splunk/var/run/searchpeers/MyIndexer1.local.com-1397750703/apps/search/lookups/MyLookupFile.csv

[MyIndexer2.local.com] Empty csv lookup file (contains only a header) for table 'MyLookupFile': /opt/splunk/var/run/searchpeers/MyIndexer2.local.com-1397750703/apps/search/lookups/MyLookupFile.csv

0 Karma

Communicator

Any luck with this ? I am having simialr problem with Qualys KB CSV

0 Karma

Motivator

I tried to change this value in the limits.conf as a first workaround, so that the lookup is not indexed.

[lookup] max_memtable_bytes = 50000000

I'm not sure whether this works. Is it possible to run a search thats shows the folder & size of the .csv (and the index if it exists)?

0 Karma

SplunkTrust
SplunkTrust

That means your lookup file is empty. What is generating the lookup file?

Motivator

It has to be on the search head as well, because sometimes the searchresults are correct. the error seems to appear randomly.

0 Karma

SplunkTrust
SplunkTrust

Yes, They only really need to be on the search head.

0 Karma

Champion

Shouldn't the look up be placed in search head only?

0 Karma

Motivator

Unfortunately the IRC doesn't work at my side at the moment.

I think we've looked at the file on the indexer.

0 Karma

SplunkTrust
SplunkTrust

Where did you look? On indexer1? or on the Search Head? Also - I am on IRC #splunk -efnet if you want to chat directly.

0 Karma

Motivator

But it is not empty, we've opened it and it looks fine.
The lookupfile is created by a splunk search

my search | outputlookup lookup.csv

The lookup file is around 28MB and an index is created as well.

Sometimes it works, sometimes the error appears. It's really strange

0 Karma