Splunk Search

Lookup csv missing in definitions

cdstealer
Contributor

Hi, Hopefully a quick one 🙂 I have a user that can upload lookup table files, but when a lookup definition is created, the file does not appear in the lookup file list. The uploaded file is present and the permissions seem good. The file does not appear even as the admin user, so I know it's not a perms issue.
I've even executed a debug/refresh to no avail.
Has anyone come across this before?

TIA
Steve

0 Karma
1 Solution

cdstealer
Contributor

Looks like after running "| inputlookup " it forced it to be seen?

View solution in original post

liammcmenamin
Engager

That also didn't work for me. What did work was:
- open the app that contains the lookup file
- goto settings --> lookups --> Lookup definitions. The active app will be selected.
- click create new lookup definition
- the file should be visible!

lmonahan
Path Finder

Worked for me too!

0 Karma

bipinb555
Engager

This worked for me

cdstealer
Contributor

Looks like after running "| inputlookup " it forced it to be seen?

eugenek
Path Finder

It didn't for me 😞

0 Karma

dcarmack_splunk
Splunk Employee
Splunk Employee

Can you successfully call the lookup using the inputlookup command?

0 Karma

cdstealer
Contributor

Hi D, Yes we are able to view the contents via "| inputlookup"
Cheers

0 Karma

cdstealer
Contributor

Sigh.. Without changing anything, I've just rechecked and the table file now appears in the drop down. I have no idea what happened. Did displaying the file force something?

Thanks anyway 🙂

0 Karma
Get Updates on the Splunk Community!

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...