Splunk Search

Splunk lookup

santhipriya
Engager

I have a 3 node search head cluster and distributed indexers we are getting below error when running any type of search . suggest any ways to avoid it

error: (indexers)..........of 41 peers omitted] Could not load lookup=LOOKUP-connect_glpi

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

the message is saying the there's a missed loookup (probaly automatic) in your search head cluster.

you have to understand in which app it's located and then create or disable it.

Ciao.

Giuseppe

0 Karma

santhipriya
Engager

Hi @gcusello 

I was able to find out those in automatic lookups and deleted ,the errors are fixed now . Thanks.!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...