Splunk Search

Splunk App for Anomaly Detection - "Could not load lookup=LOOKUP-HTTP_STATUS No matching fields exist."

danielbb
Motivator

In Step 2 "Add the Dataset" of "Create Anomaly Job" within the Splunk App for Anomaly Detection, when running the following SPL, we get the warning- 

 

 

 

index=wineventlog_security
| timechart count

"Could not load lookup=LOOKUP-HTTP_STATUS No matching fields exist."

 

 

 

 

What can it be?

We use the following versions -

Splunk App for Anomaly Detection - 1.1.0

Python for Scientific Computing  - 4.1.2 

Splunk Machine Learning Toolkit  - 5.4.0

Labels (1)
0 Karma

kcurtis
Splunk Employee
Splunk Employee

Can you confirm whether your original search returns > 0 events by running it in the search bar on the "Search" tab in AnomalyApp (or in Search & Reporting)?  This message may be shown because the search is returning 0 events.  We expect to have a fix for this, so our error message is more informative, in our next patch release of AnomalyApp.

0 Karma

danielbb
Motivator

@VatsalJaganiI looked in a couple of environments and I don't see it as automatic lookup. Any ideas?

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@danielbb - What do you mean by a couple of environments? You need to check in the environment/SearchHead which is generating this error for you.

And there has to be automatic lookup. If you don't see it try to find it inside props.conf from the backend.

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@danielbb - This automatic lookup could be present in any App.

You can try to find where it is present by going to Splunk UI > Lookups > Automatic lookups and select All App and Any Owner and filter for HTTP_STATUS and trying to find which App contains this lookup. You should be able to fix it from there as well.

 

I hope this helps!!!

Get Updates on the Splunk Community!

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering. Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...