Splunk Search

Splunk lookup

santhipriya
Engager

I have a 3 node search head cluster and distributed indexers we are getting below error when running any type of search . suggest any ways to avoid it

error: (indexers)..........of 41 peers omitted] Could not load lookup=LOOKUP-connect_glpi

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

the message is saying the there's a missed loookup (probaly automatic) in your search head cluster.

you have to understand in which app it's located and then create or disable it.

Ciao.

Giuseppe

0 Karma

santhipriya
Engager

Hi @gcusello 

I was able to find out those in automatic lookups and deleted ,the errors are fixed now . Thanks.!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...