Splunk Search

How to troubleshoot “Error in 'inputlookup' command: External lookup table 'inputlookup' returned error code 13053..."?

quantum1
Engager

Hello I'm getting this error when I go into the Enterprise console and look at the security posture it's been going on for a few days any idea how to troubleshoot this?

Thanks in advance

 

I would appreciate the help as I am relatively new to Splunk and need some guidance.

Labels (1)

Quantum
Explorer

Is this a generic error,? I am very new to Splunk and I am sure that there is a relevant log that could give me more information on this what would that log be? would it be on one of the servers like the search head I am kind of lost here any help would be appreciated.

0 Karma

Quantum
Explorer

PreforkedSearchesManager-0] - preforked process=0/175613 died on exception (exit code=111): Error in 'inputlookup' command: External lookup table 'inputlookup' returned error code 13053. Results might be incorrect

Okay I went into the Splunk D log and found this  above does anybody know what this exit 111 means or where I can find more information about this error?

 

 

0 Karma

Quantum
Explorer

Error in 'inputlookup' command: External command based lookup 'es_notable_events' is not available because KV Store initialization has failed. Contact your system administrator.

 

 

Okay I stopped and started Splunk on this server. now I am getting this key Value Store error how do I fix this?

 

 

0 Karma

Quantum
Explorer

trying this systemctl restart splunk

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...