Splunk Search

Lookup csv missing in definitions

cdstealer
Contributor

Hi, Hopefully a quick one 🙂 I have a user that can upload lookup table files, but when a lookup definition is created, the file does not appear in the lookup file list. The uploaded file is present and the permissions seem good. The file does not appear even as the admin user, so I know it's not a perms issue.
I've even executed a debug/refresh to no avail.
Has anyone come across this before?

TIA
Steve

0 Karma
1 Solution

cdstealer
Contributor

Looks like after running "| inputlookup " it forced it to be seen?

View solution in original post

liammcmenamin
Engager

That also didn't work for me. What did work was:
- open the app that contains the lookup file
- goto settings --> lookups --> Lookup definitions. The active app will be selected.
- click create new lookup definition
- the file should be visible!

lmonahan
Path Finder

Worked for me too!

0 Karma

bipinb555
Engager

This worked for me

cdstealer
Contributor

Looks like after running "| inputlookup " it forced it to be seen?

eugenek
Path Finder

It didn't for me 😞

0 Karma

dcarmack_splunk
Splunk Employee
Splunk Employee

Can you successfully call the lookup using the inputlookup command?

0 Karma

cdstealer
Contributor

Hi D, Yes we are able to view the contents via "| inputlookup"
Cheers

0 Karma

cdstealer
Contributor

Sigh.. Without changing anything, I've just rechecked and the table file now appears in the drop down. I have no idea what happened. Did displaying the file force something?

Thanks anyway 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...