Splunk Search

Error message while searching from the search head

adidibra
Engager

Hello,

I am getting the following error while searching in splunk.

  • Could not load lookup=LOOKUP-cisco_pix_severity_lookup
  • Could not load lookup=LOOKUP-citrix_netscaler_availability_status
  • Could not load lookup=LOOKUP-citrix_netscaler_ha_states
  • Could not load lookup=LOOKUP-f5_icontrol_availability_status
  • Could not load lookup=LOOKUP-f5_icontrol_ha_states

I copied the apps from another splunk deployer and now I getting these errors. I see the lookup csv files are there but still the error persists.

Am I missing something? Please advise.

Thanks

Labels (1)
0 Karma

tscroggins
Influencer

@adidibra 

In a distributed environment, check each app's default/distsearch.conf and local/distsearch.conf on the search head for replicationSettings:refineConf, replicationWhitelist, and replicationBlacklist stanzas that may be preventing the lookups from being added to the knowledge bundle.

0 Karma

adidibra
Engager
@tscroggins Thanks for the advice
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...