Splunk Search

Lookup Does Not Exist Error- Help

katzr
Path Finder

I know there are a lot of answers on this topic- but I think I have completed all of the steps offered. One of my users is getting the error message that the lookup does not exist or is not available, even though I can see the lookup and my report.

The permissions are set so that all roles can read the lookup. The object is set to appear in all apps. The report is loading fine for me, but one of my users who has some of the same roles as me can't see the lookup. When the user searches |inputlookup LookUpName the lookup loads for her then- but not in the report. Thank you for the help!!

woodcock
Esteemed Legend

Make sure that the lookup name matches everywhere AND the lookup filename matches everywhere. One time I was referencing myLookupFile.csv but the file that I had uploaded was myLoookupFile.csv (3 o's instead of 2). It took me a LONG time to spot it.

0 Karma

katzr
Path Finder

No that does not solve the problem- any other suggestions?

0 Karma

katzr
Path Finder

the permissions are global also

0 Karma

katzr
Path Finder

Also I have the same permissions as the user who is not able to load the lookup but I am able

0 Karma

katzr
Path Finder

the app that I am using is search

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...