Splunk Search

Lookup csv missing in definitions

Contributor

Hi, Hopefully a quick one 🙂 I have a user that can upload lookup table files, but when a lookup definition is created, the file does not appear in the lookup file list. The uploaded file is present and the permissions seem good. The file does not appear even as the admin user, so I know it's not a perms issue.
I've even executed a debug/refresh to no avail.
Has anyone come across this before?

TIA
Steve

0 Karma
1 Solution

Contributor

Looks like after running "| inputlookup " it forced it to be seen?

View solution in original post

That also didn't work for me. What did work was:
- open the app that contains the lookup file
- goto settings --> lookups --> Lookup definitions. The active app will be selected.
- click create new lookup definition
- the file should be visible!

Engager

This worked for me

0 Karma

Contributor

Looks like after running "| inputlookup " it forced it to be seen?

View solution in original post

Path Finder

It didn't for me 😞

0 Karma

Splunk Employee
Splunk Employee

Can you successfully call the lookup using the inputlookup command?

0 Karma

Contributor

Hi D, Yes we are able to view the contents via "| inputlookup"
Cheers

0 Karma

Contributor

Sigh.. Without changing anything, I've just rechecked and the table file now appears in the drop down. I have no idea what happened. Did displaying the file force something?

Thanks anyway 🙂

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!