Splunk Search

Splunk shows "The lookup table does not exist"

peterchow
Explorer

My splunk show the following message suddenly but I don know how to solve it. I tried to search 'ns_log' and 'ns_msg_lookup' but cannot find it. Please advice. Thanks

The lookup table 'ns_msg_lookup' does not exist. It is referenced by configuration 'ns_log'.
[subsearch]: The lookup table 'ns_msg_lookup' does not exist. It is referenced by configuration 'ns_log'.
Tags (1)
0 Karma

sander980
Explorer

I found this in the Citrix Netscaler app - Splunk_TA_Citrix-NetScaler

0 Karma

sundareshr
Legend

If you have admin privileges, you should see the lookup table listed in Settings > Lookups > Lookup Table Files If you do not have admin privileges, you may not see it, if you haven't been given permissions. Contact your Splunk Admin.

If you are the admin, see if any new automatic lookups have been set and disable them.

0 Karma

gcusello
SplunkTrust
SplunkTrust

check the permission of your user, maybe you haven't the correct grants to the lookup.
Bye.
Giuseppe

0 Karma

peterchow
Explorer

As i mentioned, I cannot find those lookup table

0 Karma

sheamus69
Communicator

Is the lookup listed in Settings > Lookups > Lookup Table Files?

0 Karma

gcusello
SplunkTrust
SplunkTrust

go in your $SPLUNK_HOME/etc/apps/yourapp/metadata/ and search in file local.meta the name of your lookup, you should find the lookup.
If you don't find it in yourapp directory search it in other apps.
Bye.
Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...