Splunk Search

How to troubleshoot “Error in 'inputlookup' command: External lookup table 'inputlookup' returned error code 13053..."?

quantum1
Engager

Hello I'm getting this error when I go into the Enterprise console and look at the security posture it's been going on for a few days any idea how to troubleshoot this?

Thanks in advance

 

I would appreciate the help as I am relatively new to Splunk and need some guidance.

Labels (1)

Quantum
Explorer

Is this a generic error,? I am very new to Splunk and I am sure that there is a relevant log that could give me more information on this what would that log be? would it be on one of the servers like the search head I am kind of lost here any help would be appreciated.

0 Karma

Quantum
Explorer

PreforkedSearchesManager-0] - preforked process=0/175613 died on exception (exit code=111): Error in 'inputlookup' command: External lookup table 'inputlookup' returned error code 13053. Results might be incorrect

Okay I went into the Splunk D log and found this  above does anybody know what this exit 111 means or where I can find more information about this error?

 

 

0 Karma

Quantum
Explorer

Error in 'inputlookup' command: External command based lookup 'es_notable_events' is not available because KV Store initialization has failed. Contact your system administrator.

 

 

Okay I stopped and started Splunk on this server. now I am getting this key Value Store error how do I fix this?

 

 

0 Karma

Quantum
Explorer

trying this systemctl restart splunk

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...