Splunk Search

External lookup that worked in Splunk 5 failing in Splunk 6

keerthana_k
Communicator

Hi,

We have an external lookup script in our application which uses some external database for performing lookup. It was working fine until recently.

We upgraded our Splunk version to 6.1.3. Suddenly the script is returning the following error:
"Script for lookup table 'external_lookup' returned error code 1. Results may be incorrect."

I tried running the script separately by providing input csv file and it worked without any error. So I am assuming this is due to the upgradation.

Below is my stanza in transforms.conf:

[external_lookup]
external_cmd = external_lookup.py
fields_list = field1 field2 field3 field4 field5 field6 field7

where field1 is the input field and the rest are output fields.

Please help me out with the issue.

Thanks,
Keerthana

Tags (1)
0 Karma

neelamssantosh
Contributor

Kindly check the props.conf and permissions @ App level too (not lookup's)..
make sure lookup/bnigeoip.csv --> lookup definition --> automatic lookup file every thing are in place and with permissions.

0 Karma

keerthana_k
Communicator

Hi,

We don't need props.conf as we are using the lookup in search query. The app level permission is set to

[]
export = system
0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...