Splunk Search

Splunk is not able to idetnify transforms.conf lookup configuration



I have a csv file uploaded in the location /opt/splunk/etc/apps/search/lookups/. My transforms file is in /opt/splunk/etc/apps/search/local with configuration as



I am trying to run a search query using this lookup command to map the error code from the event to the error codes in the csv file. But Splunk keeps saying "Error in 'lookup' command: Could not construct lookup "

This is my search query 

base_search | lookup error_codes error_code_spl OUTPUT error_code_desc, error_code_sol

I even tried to make the lookup file and transforms global by moving it to /opt/splunk/etc/system/lookups and /opt/splunk/etc/system/local/transforms.conf, but nothing works. 

Am I missing something here?. Please help.

Labels (1)
0 Karma


hi @surejsajeev,

Check the permissions of the CSV file - error_codes.csv and lookup definition - error_codes. Are they shared with the search app?
To check/change permissions for CSV file got to Settings >> Lookup >> Lookup table files.

To check/change permissions for the lookup definitions permissions got to Settings >> Lookup>> Lookup definitions.


If this reply helps you, a like would be appreciated.

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!