Splunk Search

Lookup csv missing in definitions

cdstealer
Contributor

Hi, Hopefully a quick one 🙂 I have a user that can upload lookup table files, but when a lookup definition is created, the file does not appear in the lookup file list. The uploaded file is present and the permissions seem good. The file does not appear even as the admin user, so I know it's not a perms issue.
I've even executed a debug/refresh to no avail.
Has anyone come across this before?

TIA
Steve

0 Karma
1 Solution

cdstealer
Contributor

Looks like after running "| inputlookup " it forced it to be seen?

View solution in original post

liammcmenamin
Engager

That also didn't work for me. What did work was:
- open the app that contains the lookup file
- goto settings --> lookups --> Lookup definitions. The active app will be selected.
- click create new lookup definition
- the file should be visible!

lmonahan
Path Finder

Worked for me too!

0 Karma

bipinb555
Engager

This worked for me

cdstealer
Contributor

Looks like after running "| inputlookup " it forced it to be seen?

eugenek
Path Finder

It didn't for me 😞

0 Karma

dcarmack_splunk
Splunk Employee
Splunk Employee

Can you successfully call the lookup using the inputlookup command?

0 Karma

cdstealer
Contributor

Hi D, Yes we are able to view the contents via "| inputlookup"
Cheers

0 Karma

cdstealer
Contributor

Sigh.. Without changing anything, I've just rechecked and the table file now appears in the drop down. I have no idea what happened. Did displaying the file force something?

Thanks anyway 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...