Splunk Search

How to troubleshoot “Error in 'inputlookup' command: External lookup table 'inputlookup' returned error code 13053..."?

quantum1
Engager

Hello I'm getting this error when I go into the Enterprise console and look at the security posture it's been going on for a few days any idea how to troubleshoot this?

Thanks in advance

 

I would appreciate the help as I am relatively new to Splunk and need some guidance.

Labels (1)

Quantum
Explorer

Is this a generic error,? I am very new to Splunk and I am sure that there is a relevant log that could give me more information on this what would that log be? would it be on one of the servers like the search head I am kind of lost here any help would be appreciated.

0 Karma

Quantum
Explorer

PreforkedSearchesManager-0] - preforked process=0/175613 died on exception (exit code=111): Error in 'inputlookup' command: External lookup table 'inputlookup' returned error code 13053. Results might be incorrect

Okay I went into the Splunk D log and found this  above does anybody know what this exit 111 means or where I can find more information about this error?

 

 

0 Karma

Quantum
Explorer

Error in 'inputlookup' command: External command based lookup 'es_notable_events' is not available because KV Store initialization has failed. Contact your system administrator.

 

 

Okay I stopped and started Splunk on this server. now I am getting this key Value Store error how do I fix this?

 

 

0 Karma

Quantum
Explorer

trying this systemctl restart splunk

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...