Splunk Search

Lookups within a search head pool not finding shared storage lookup table

willthames2
Path Finder

I can replicate this behaviour within a search head pool by

  • Add a Lookup Table, and upload a CSV file
  • Change permissions to be App
  • Note that location is now <sharedstorage>/etc/apps/<app>/lookups/<csvfile> (and not <splunkroot>/etc/apps/<app>/lookups/<csvfile>
  • Try to add a lookup definition, but the lookup table is not in the dropdown
  • If I add the lookup table to the <splunkroot>/etc/apps/<app>/lookups/<csvfile>, I can add the lookup definition

What I need is for the lookup definition dropdown to be able to find lookup tables under <sharedstorage>/etc/apps/<app>/lookups/<csvfile>

1 Solution

ewoo
Splunk Employee
Splunk Employee

From which app are you using Manager?

One "wrinkle" to the UI -- the dropdown of available lookup table files is based on the app context of Manager, not the destination app you choose for the lookup definition.

In other words, if you are using Manager from the Home app while writing these lookup table files and definitions to the "search" app via the "destination app" dropdowns, then this is expected (though somewhat confusing) behavior.

The workaround is to use Manager from the search app or to share the lookup table globally (across all apps).

View solution in original post

ewoo
Splunk Employee
Splunk Employee

From which app are you using Manager?

One "wrinkle" to the UI -- the dropdown of available lookup table files is based on the app context of Manager, not the destination app you choose for the lookup definition.

In other words, if you are using Manager from the Home app while writing these lookup table files and definitions to the "search" app via the "destination app" dropdowns, then this is expected (though somewhat confusing) behavior.

The workaround is to use Manager from the search app or to share the lookup table globally (across all apps).

willthames2
Path Finder

That is confusing behaviour! Thanks for the explanation!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...