Splunk Search

Splunk search error "Indexers error Could not load lookup=LOOKUP-XXXX " I cant find these LOOKUP anywhere

aamer86
Path Finder

I have created a lookup for a threat feed CSV file we are using. 
After deleting all the Lookup CSV files and removing all the peops.conf and Transforms.conf inputs for this lookup from the the deployer, CMn SHs and indexers I still see an error splunk_error.jpg

Labels (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

The first thing to check would be the method used to remove the artifacts.  Did you remove and modify from the file system or did you use Splunk Web to do so?  If former, you'll also need to restart Splunk server.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...