Splunk Search

Splunk shows "The lookup table does not exist"

peterchow
Explorer

My splunk show the following message suddenly but I don know how to solve it. I tried to search 'ns_log' and 'ns_msg_lookup' but cannot find it. Please advice. Thanks

The lookup table 'ns_msg_lookup' does not exist. It is referenced by configuration 'ns_log'.
[subsearch]: The lookup table 'ns_msg_lookup' does not exist. It is referenced by configuration 'ns_log'.
Tags (1)
0 Karma

sander980
Explorer

I found this in the Citrix Netscaler app - Splunk_TA_Citrix-NetScaler

0 Karma

sundareshr
Legend

If you have admin privileges, you should see the lookup table listed in Settings > Lookups > Lookup Table Files If you do not have admin privileges, you may not see it, if you haven't been given permissions. Contact your Splunk Admin.

If you are the admin, see if any new automatic lookups have been set and disable them.

0 Karma

gcusello
SplunkTrust
SplunkTrust

check the permission of your user, maybe you haven't the correct grants to the lookup.
Bye.
Giuseppe

0 Karma

peterchow
Explorer

As i mentioned, I cannot find those lookup table

0 Karma

sheamus69
Communicator

Is the lookup listed in Settings > Lookups > Lookup Table Files?

0 Karma

gcusello
SplunkTrust
SplunkTrust

go in your $SPLUNK_HOME/etc/apps/yourapp/metadata/ and search in file local.meta the name of your lookup, you should find the lookup.
If you don't find it in yourapp directory search it in other apps.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...