Splunk Search

Lookup csv missing in definitions

cdstealer
Contributor

Hi, Hopefully a quick one 🙂 I have a user that can upload lookup table files, but when a lookup definition is created, the file does not appear in the lookup file list. The uploaded file is present and the permissions seem good. The file does not appear even as the admin user, so I know it's not a perms issue.
I've even executed a debug/refresh to no avail.
Has anyone come across this before?

TIA
Steve

0 Karma
1 Solution

cdstealer
Contributor

Looks like after running "| inputlookup " it forced it to be seen?

View solution in original post

liammcmenamin
Engager

That also didn't work for me. What did work was:
- open the app that contains the lookup file
- goto settings --> lookups --> Lookup definitions. The active app will be selected.
- click create new lookup definition
- the file should be visible!

lmonahan
Explorer

Worked for me too!

0 Karma

bipinb555
Engager

This worked for me

cdstealer
Contributor

Looks like after running "| inputlookup " it forced it to be seen?

View solution in original post

eugenek
Path Finder

It didn't for me 😞

0 Karma

dcarmack_splunk
Splunk Employee
Splunk Employee

Can you successfully call the lookup using the inputlookup command?

0 Karma

cdstealer
Contributor

Hi D, Yes we are able to view the contents via "| inputlookup"
Cheers

0 Karma

cdstealer
Contributor

Sigh.. Without changing anything, I've just rechecked and the table file now appears in the drop down. I have no idea what happened. Did displaying the file force something?

Thanks anyway 🙂

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!