Splunk Search

Inputlookup subsearch shows invalid lookup

mdsnmss
SplunkTrust
SplunkTrust

I have a user who is receiving the error:

No matching fields exist [subsearch]: The lookup table <-lookup>.csv is invalid.

This is the result of the line: | JOIN <field> [inputlookup <lookup>.csv]

The search itself runs successfully with multiple other accounts so I am assuming it is a permissions issue. I have gone into the lookup table and definition and both are shared globally and have the user listed with read access. I've also confirmed the field referenced in the join is in both the lookup table and definition.

Any idea why it is not allowing this user to run the search?

0 Karma
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

Kept troubleshooting and it was a permissions issue. The account needed access to the index, the lookup table, and the app the lookup table was in. We had the first two and with the lookup table shared globally and permissions granted to the user for read access to it thought it should work outside of the app context. Adding read access to the app it was contained in allowed the search to run.

View solution in original post

mdsnmss
SplunkTrust
SplunkTrust

Kept troubleshooting and it was a permissions issue. The account needed access to the index, the lookup table, and the app the lookup table was in. We had the first two and with the lookup table shared globally and permissions granted to the user for read access to it thought it should work outside of the app context. Adding read access to the app it was contained in allowed the search to run.

sbbadri
Motivator

try below

| JOIN [|inputlookup .csv]

i think your are missing pipe in fornt of inputlookup

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

It works with or without the pipe for my account.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti &#x1f389; —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...