- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I configured external lookup definition with a script I built. However, the lookup command fails with the following message.
Error in 'lookup' command: The lookup table 'mylookup' does not exist or is not available.
SPL Command:
... | lookup mylookup myfield
$SPLUNK_HOME/etc/apps/myapp/local/transforms.conf:
[mylookup]
external_cmd = get_lookup.py
fields_list =Title,Genre,Country,imdbRating
I placed get_lookup.py in $SPLUNK_HOME/etc/apps/myapp/bin/.
What's wrong with the lookup definition?
(Splunk Ver: 6.5 / OS: Mac OS X)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
What is the permission of lookup definition (Private, App only, or Global) and which app did you execute lookup command in?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
What is the permission of lookup definition (Private, App only, or Global) and which app did you execute lookup command in?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You're right. I created it in custom app with App permission but used the command at search app. Thank you.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/cf55c/cf55c824a7d5e0546d86a318007bf13b04f08bcc" alt="cdoebert cdoebert"
Does Splunk have access to get_lookup.py? The file perms might be overriding the dir perms.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I granted 755 to the py script. The owner is the same as the one who runs splunkd.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
Did you restart Splunk after you placed that file?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, of course I did.
data:image/s3,"s3://crabby-images/2f34b/2f34b8387157c32fbd6848ab5b6e4c62160b6f87" alt=""