- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I configured external lookup definition with a script I built. However, the lookup command fails with the following message.
Error in 'lookup' command: The lookup table 'mylookup' does not exist or is not available.
SPL Command:
... | lookup mylookup myfield
$SPLUNK_HOME/etc/apps/myapp/local/transforms.conf:
[mylookup]
external_cmd = get_lookup.py
fields_list =Title,Genre,Country,imdbRating
I placed get_lookup.py in $SPLUNK_HOME/etc/apps/myapp/bin/.
What's wrong with the lookup definition?
(Splunk Ver: 6.5 / OS: Mac OS X)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

What is the permission of lookup definition (Private, App only, or Global) and which app did you execute lookup command in?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

What is the permission of lookup definition (Private, App only, or Global) and which app did you execute lookup command in?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You're right. I created it in custom app with App permission but used the command at search app. Thank you.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Does Splunk have access to get_lookup.py? The file perms might be overriding the dir perms.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I granted 755 to the py script. The owner is the same as the one who runs splunkd.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Did you restart Splunk after you placed that file?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, of course I did.
