- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk search error "Indexers error Could not load lookup=LOOKUP-XXXX " I cant find these LOOKUP anywhere
aamer86
Path Finder
04-09-2022
11:33 AM
I have created a lookup for a threat feed CSV file we are using.
After deleting all the Lookup CSV files and removing all the peops.conf and Transforms.conf inputs for this lookup from the the deployer, CMn SHs and indexers I still see an error
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yuanliu

SplunkTrust
04-09-2022
03:16 PM
The first thing to check would be the method used to remove the artifacts. Did you remove and modify from the file system or did you use Splunk Web to do so? If former, you'll also need to restart Splunk server.
