Splunk Search

Getting error in splunk cloud while running every search in the splunk cloud

samsingnok52
Engager

Error :

" Error 'Could not find all of the specified lookup fields in the lookup table.' for conf '(?::){0}XmlWinEventLog:*' and lookup table 'identity_lookup_expanded'."

The above error is getting generated after i tried to populate a lookup which was created already by the splunk ,"'identity_lookup_expanded"...

Kindly suggest to resolve this issue.

Tags (1)
0 Karma

jbarlow_splunk
Splunk Employee
Splunk Employee

seems to be a problem with the csv/lookup.. as it is splunk cloud.. will need to log a case to get cloud support team to look at it

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...