Splunk Search

How to access a lookup created in one app in another?

mscomms
Path Finder

Hi All,

Splunk Enterprise 8.2.4 Clustered

I have an issue where I have an existing app with a lookup listing all devices we are monitoring and I have a new app where I pull a subset of these devices to provide a dashboard for the team that supports them.

The underlying search

"| inputlookup NocIP.csv
| search Datasource="Eaton" OR Datasource="eltek"

Works fine within the original app and works fine from the new app using my "General user" which has admin rights but using a user set up for the support team using the new app the search fails with the following result

mscomms_0-1646216290421.png

the lookup table file has the following permissions set

mscomms_1-1646216401365.png


The lookup definition permissions are set like this

mscomms_2-1646216525086.png


The role for the support team is cloned from the role that uses the original app

mscomms_3-1646216773230.png


Inheritance

mscomms_4-1646216808266.png

Cababilities

mscomms_5-1646216867877.png


This app doesn't use any indexes and there are no Restrictions in place
The resources are

mscomms_6-1646216970584.png

The user is 

mscomms_7-1646217030537.png


with the Config

mscomms_8-1646217061985.png

This is doing my head in because it looks like it should work but isn't, can anyone see what I have missed?

Cheers

Mike

Labels (1)
Tags (2)
0 Karma

mscomms
Path Finder

@gcusello  I have set the permission to 

mscomms_0-1646224585099.png


Its still not workin

0 Karma

mscomms
Path Finder

@gcusello  here is the definition

mscomms_0-1646229469394.png

 

0 Karma

mscomms
Path Finder

mscomms_0-1646229528357.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mscomms,

I don't see anything wrong!

could you try to run the search without where conditions?

| inputlookup NoxIP.csv

I found something similar in another question https://community.splunk.com/t5/Splunk-Search/Error-subsearch-The-lookup-table-dns-serves-csv-requir...

Ciao.

Giuseppe

0 Karma

mscomms
Path Finder

I have checked that article but I definatly haven't got a typo as this search copied and pasted ito a search window in the new app using my admin user works fine

0 Karma

mscomms
Path Finder

I have already tried that but have retested and it is still failing

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mscomms.,

could you share the screenshot of the lookup definition?

Ciao.

Giuseppe

0 Karma

mscomms
Path Finder

All groups have read access, the admin and power grants are for write access

mscomms_0-1646223443583.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mscomms,

there isn't any additional check I can think, please try to give read grants to User on those lookup and lookup definition.

Ciao.

Giuseppe

0 Karma

mscomms
Path Finder

@gcusello The read permissions are set for all roles on the system so both

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hiu @mscomms,

yes, I've seen, probably it isn't relevant, but, please, try to do this.

Give wrtite grants to User on lookup and lookup definition.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mscomms,

did you tried to give to your lookup and lookup definition grants for your role or for the "user" role?

You gave only grants fro admin and power user roles and you haven't non of them.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...