Receiving multiple pop-ups when trying to run a search:
The lookup table 'windows_event_descriptions' does not exist. It is referenced by configuration 'source::(MonitorWare|NTSyslog|Snare|WinEventLog|WMI:WinEventLog)...'.
Added the below stanza in metadata/local.meta also metadata/default.meta
export = system
Also, found that the csv "windowseventdescriptions" is not present in the lookups folder of the application.
Do I need to generate a csv? If yes, what fields would the present in the csv?
This is an automatic lookup, so how would Splunk create a automatic lookup?