Error :
" Error 'Could not find all of the specified lookup fields in the lookup table.' for conf '(?::){0}XmlWinEventLog:*' and lookup table 'identity_lookup_expanded'."
The above error is getting generated after i tried to populate a lookup which was created already by the splunk ,"'identity_lookup_expanded"...
Kindly suggest to resolve this issue.
seems to be a problem with the csv/lookup.. as it is splunk cloud.. will need to log a case to get cloud support team to look at it