Here is my transforms.conf for the lookup table in question:
[ossim_plugins] filename = ossim_plugins.csv max_matches = 1
Here is an example of one of the searches that references the lookup table:
search = sourcetype=ossim "Event received" NOT ((plugin_id>=1001 AND plugin_id<=1131) OR plugin_id=1597) | lookup ossim_plugins plugin_id OUTPUT plugin_name | timechart count by plugin_name
But Splunk is occasionally throwing the following error:
The lookup table 'ossim_plugins' does not exist. It is referenced by configuration 'ossim_plugins'.
The lookup table ossim_plugins.csv is located in the lookups directory of the app that the searches and dashboards are defined in.
Any ideas?
Thx.
Never mind... Somehow an entry was made in props.conf with the title [ossim_plugins] and the content of the stanza was garbled.