Splunk Search
Highlighted

How do you resolve the error "The lookup table 'windows_event_descriptions' does not exist"?

New Member

Running Splunk 6.2.4. Search results are displayed but message says "22 errors occured while the search was executing. Therefore, search results might be incomplete."

  • The lookup table 'windowseventdescriptions' does not exist. It is referenced by configuration 'source::WinEventLog:Application|host::server001|WinEventLog:Application'.
  • The lookup table 'windowseventdescriptions' does not exist. It is referenced by configuration 'source::WinEventLog:Security|host::server002|WinEventLog:Security'.
Tags (2)
0 Karma
Highlighted

Re: How do you resolve the error "The lookup table 'windows_event_descriptions' does not exist"?

SplunkTrust
SplunkTrust

Do you have any automatic lookup setup (for the lookup table name mentioned in the error) and its no longer available?

0 Karma
Highlighted

Re: How do you resolve the error "The lookup table 'windows_event_descriptions' does not exist"?

Contributor

Can you check your lookup definitions and check if the lookup exists,

What is the search string you tried , |inputlookup "csvname.csv" ??

Highlighted

Re: How do you resolve the error "The lookup table 'windows_event_descriptions' does not exist"?

Champion

I typically see this problem under two conditions.

  1. If the csv has been delete.
  2. if an automatic lookup is reference a csv which is private or out of its application scope. To fix this error simply find the lookup then the csv it referencing and make the csv global or app with read permission for everyone.
0 Karma
Highlighted

Re: How do you resolve the error "The lookup table 'windows_event_descriptions' does not exist"?

New Member

Thanks,

  1. I looked in settings > lookups > lookup table files > and it doesn't list windowseventdescriptions.csv
  2. I do see the lookup table "windowseventdescriptions" being referenced in Automatic lookups by Name = "source::(MonitorWare|NTSyslog|Snare|WinEventLog|WMI:WinEventLog)... : LOOKUP-EventCodeDescriptionforwindows" and used by the app splunkappwindows_infrastructure

Since its throwing the same error for 20 individual systems I'm guessing this lookup table is missing from our universal forwarders... ???

0 Karma
Highlighted

Re: How do you resolve the error "The lookup table 'windows_event_descriptions' does not exist"?

Champion

The lookup is not generated by your universal forwarder but by your search head. I would disabled the automatic lookup or setup for to generate a new csv.

0 Karma
Highlighted

Re: How do you resolve the error "The lookup table 'windows_event_descriptions' does not exist"?

New Member

Is there a way to disable an automatic lookup that used by an App. Looks like that auto lookup is from the Splunk App for Windows Infrastructure >>> splunkappwindows_infrastructure 1.1.3

Doesn't look like you can delete it either...

How would you get it to generate a new csv?

0 Karma
Highlighted

Re: How do you resolve the error "The lookup table 'windows_event_descriptions' does not exist"?

Engager

I was able to resolve this error just now. Go to settings -> lookups -> lookup table files, change the App context dropdown to "All", and search for windowseventdescriptions. It will show you the path of the file, mine is:
C:\Program Files\Splunk\etc\apps\splunk_app_windows_infrastructure\lookups\windows_event_descriptions.csv
-- and when I looked in this folder, the file was indeed missing.

I went to splunkbase, downloaded the Splunk App For windows Infrastructure app, and unpacked the .TGZ manually. The windowseventdescriptions.csv file is contained inside here, I copied it into the above-mentioned folder, and done - no more errors on search. I found more files in here than were in the lookups folder on the system, so I actually copied all 30 of the csv's from the archive, overwriting any already present.

Somehow during my splunk upgrades and splunk app for windows infrastructure upgrades, this file got lost. My splunk app manager showed app for windows infrastructure as being up-to-date.

¯\_(ツ)_/¯ Whatever, I'm happy I got mine to work and I hope this helps you.

Highlighted

Re: How do you resolve the error "The lookup table 'windows_event_descriptions' does not exist"?

Explorer

This has worked for me as well. but while using the whosthere app - the real-time dashboard does not renders.

0 Karma
Highlighted

Re: How do you resolve the error "The lookup table 'windows_event_descriptions' does not exist"?

Engager

Coming back to update this with another note --

I had done some upgrades and was having trouble with this error again, but the file was present and accessible, read permission for everyone. I finally noticed that in the LOOKUP DEFINITIONS page the lookups themselves had become DISABLED. I clicked 'enable' and presto, no more error message.

0 Karma