Splunk Search

How to troubleshoot “Error in 'inputlookup' command: External lookup table 'inputlookup' returned error code 13053..."?

quantum1
Engager

Hello I'm getting this error when I go into the Enterprise console and look at the security posture it's been going on for a few days any idea how to troubleshoot this?

Thanks in advance

 

I would appreciate the help as I am relatively new to Splunk and need some guidance.

Labels (1)

Quantum
Explorer

Is this a generic error,? I am very new to Splunk and I am sure that there is a relevant log that could give me more information on this what would that log be? would it be on one of the servers like the search head I am kind of lost here any help would be appreciated.

0 Karma

Quantum
Explorer

PreforkedSearchesManager-0] - preforked process=0/175613 died on exception (exit code=111): Error in 'inputlookup' command: External lookup table 'inputlookup' returned error code 13053. Results might be incorrect

Okay I went into the Splunk D log and found this  above does anybody know what this exit 111 means or where I can find more information about this error?

 

 

0 Karma

Quantum
Explorer

Error in 'inputlookup' command: External command based lookup 'es_notable_events' is not available because KV Store initialization has failed. Contact your system administrator.

 

 

Okay I stopped and started Splunk on this server. now I am getting this key Value Store error how do I fix this?

 

 

0 Karma

Quantum
Explorer

trying this systemctl restart splunk

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...