Splunk Search

How to troubleshoot “Error in 'inputlookup' command: External lookup table 'inputlookup' returned error code 13053..."?

quantum1
Engager

Hello I'm getting this error when I go into the Enterprise console and look at the security posture it's been going on for a few days any idea how to troubleshoot this?

Thanks in advance

 

I would appreciate the help as I am relatively new to Splunk and need some guidance.

Labels (1)

Quantum
Explorer

Is this a generic error,? I am very new to Splunk and I am sure that there is a relevant log that could give me more information on this what would that log be? would it be on one of the servers like the search head I am kind of lost here any help would be appreciated.

0 Karma

Quantum
Explorer

PreforkedSearchesManager-0] - preforked process=0/175613 died on exception (exit code=111): Error in 'inputlookup' command: External lookup table 'inputlookup' returned error code 13053. Results might be incorrect

Okay I went into the Splunk D log and found this  above does anybody know what this exit 111 means or where I can find more information about this error?

 

 

0 Karma

Quantum
Explorer

Error in 'inputlookup' command: External command based lookup 'es_notable_events' is not available because KV Store initialization has failed. Contact your system administrator.

 

 

Okay I stopped and started Splunk on this server. now I am getting this key Value Store error how do I fix this?

 

 

0 Karma

Quantum
Explorer

trying this systemctl restart splunk

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...