Splunk Search

Splunk lookup

santhipriya
Engager

I have a 3 node search head cluster and distributed indexers we are getting below error when running any type of search . suggest any ways to avoid it

error: (indexers)..........of 41 peers omitted] Could not load lookup=LOOKUP-connect_glpi

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

the message is saying the there's a missed loookup (probaly automatic) in your search head cluster.

you have to understand in which app it's located and then create or disable it.

Ciao.

Giuseppe

0 Karma

santhipriya
Engager

Hi @gcusello 

I was able to find out those in automatic lookups and deleted ,the errors are fixed now . Thanks.!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @santhipriya ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...