With latest 6.1.1 installation, the UI for adding a lookup attribute to the data model seems not working any more. Not able to attach the screenshot to post (due to insufficient Karma), but this issue is 100% reproducible. Just create a new data model and add an attribute using the default dnslookup. Is this a known issue?
The workflow for this page has been changed in Splunk 6.1, where the user needs to pick a lookup to access the dialog where input and output fields can be defined.
However, this new workflow presents issues with two types of lookups:
We hope to have this usability issues addressed soon in a 6.1.x maintenance release.
Yes, I have tried the same procedure on a 6.0.x instance, which works.
The workflow for this page has been changed in Splunk 6.1, where the user needs to pick a lookup to access the dialog where input and output fields can be defined.
However, this new workflow presents issues with two types of lookups:
We hope to have this usability issues addressed soon in a 6.1.x maintenance release.
As far as I can tell, this is not a known issue with 6.1 / 6.1.1. I would like to suggest that you open a case with Splunk Support. Please indicate if you know for a fact that this was working in 6.0.x under the same conditions.