Splunk Search

Lookups within a search head pool not finding shared storage lookup table

willthames2
Path Finder

I can replicate this behaviour within a search head pool by

  • Add a Lookup Table, and upload a CSV file
  • Change permissions to be App
  • Note that location is now <sharedstorage>/etc/apps/<app>/lookups/<csvfile> (and not <splunkroot>/etc/apps/<app>/lookups/<csvfile>
  • Try to add a lookup definition, but the lookup table is not in the dropdown
  • If I add the lookup table to the <splunkroot>/etc/apps/<app>/lookups/<csvfile>, I can add the lookup definition

What I need is for the lookup definition dropdown to be able to find lookup tables under <sharedstorage>/etc/apps/<app>/lookups/<csvfile>

1 Solution

ewoo
Splunk Employee
Splunk Employee

From which app are you using Manager?

One "wrinkle" to the UI -- the dropdown of available lookup table files is based on the app context of Manager, not the destination app you choose for the lookup definition.

In other words, if you are using Manager from the Home app while writing these lookup table files and definitions to the "search" app via the "destination app" dropdowns, then this is expected (though somewhat confusing) behavior.

The workaround is to use Manager from the search app or to share the lookup table globally (across all apps).

View solution in original post

ewoo
Splunk Employee
Splunk Employee

From which app are you using Manager?

One "wrinkle" to the UI -- the dropdown of available lookup table files is based on the app context of Manager, not the destination app you choose for the lookup definition.

In other words, if you are using Manager from the Home app while writing these lookup table files and definitions to the "search" app via the "destination app" dropdowns, then this is expected (though somewhat confusing) behavior.

The workaround is to use Manager from the search app or to share the lookup table globally (across all apps).

willthames2
Path Finder

That is confusing behaviour! Thanks for the explanation!

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...