I've got a large (170.000 rows) lookupfile that is used in several searches. I've scheduled these searches to run once per day. Sometimes the results are incorrect and the this message appears:
[[indexer1] Empty csv lookup file (contains only a header) for table 'lookup.csv': /opt/splunk/var/run/searchpeers/search-head1-1392875960/apps/App_Name/lookups/lookup.csv
So Splunk tried to create an index out of the lookup, but it failed?
Any ideas how I can fix this error?
I am having this same problem. any help would help the community
[MyIndexer1.local.com] Empty csv lookup file (contains only a header) for table 'MyLookupFile': /opt/splunk/var/run/searchpeers/MyIndexer1.local.com-1397750703/apps/search/lookups/MyLookupFile.csv
[MyIndexer2.local.com] Empty csv lookup file (contains only a header) for table 'MyLookupFile': /opt/splunk/var/run/searchpeers/MyIndexer2.local.com-1397750703/apps/search/lookups/MyLookupFile.csv
I tried to change this value in the limits.conf as a first workaround, so that the lookup is not indexed.
[lookup] max_memtable_bytes = 50000000
I'm not sure whether this works. Is it possible to run a search thats shows the folder & size of the .csv (and the index if it exists)?
But it is not empty, we've opened it and it looks fine.
The lookupfile is created by a splunk search
my search | outputlookup lookup.csv
The lookup file is around 28MB and an index is created as well.
Sometimes it works, sometimes the error appears. It's really strange