Splunk Search

Lookups within a search head pool not finding shared storage lookup table

willthames2
Path Finder

I can replicate this behaviour within a search head pool by

  • Add a Lookup Table, and upload a CSV file
  • Change permissions to be App
  • Note that location is now <sharedstorage>/etc/apps/<app>/lookups/<csvfile> (and not <splunkroot>/etc/apps/<app>/lookups/<csvfile>
  • Try to add a lookup definition, but the lookup table is not in the dropdown
  • If I add the lookup table to the <splunkroot>/etc/apps/<app>/lookups/<csvfile>, I can add the lookup definition

What I need is for the lookup definition dropdown to be able to find lookup tables under <sharedstorage>/etc/apps/<app>/lookups/<csvfile>

1 Solution

ewoo
Splunk Employee
Splunk Employee

From which app are you using Manager?

One "wrinkle" to the UI -- the dropdown of available lookup table files is based on the app context of Manager, not the destination app you choose for the lookup definition.

In other words, if you are using Manager from the Home app while writing these lookup table files and definitions to the "search" app via the "destination app" dropdowns, then this is expected (though somewhat confusing) behavior.

The workaround is to use Manager from the search app or to share the lookup table globally (across all apps).

View solution in original post

ewoo
Splunk Employee
Splunk Employee

From which app are you using Manager?

One "wrinkle" to the UI -- the dropdown of available lookup table files is based on the app context of Manager, not the destination app you choose for the lookup definition.

In other words, if you are using Manager from the Home app while writing these lookup table files and definitions to the "search" app via the "destination app" dropdowns, then this is expected (though somewhat confusing) behavior.

The workaround is to use Manager from the search app or to share the lookup table globally (across all apps).

willthames2
Path Finder

That is confusing behaviour! Thanks for the explanation!

0 Karma
Get Updates on the Splunk Community!

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...