Splunk Search

The lookup table 'dm_audit_class_type' does not exist. It is referenced by configuration 'WinEventLog:Security'

Lehanov
Explorer

Hello

Please help me this issue

The lookup table 'dm_audit_class_type' does not exist. It is referenced by configuration 'WinEventLog:Security'

It seems WinEventLog:Security is internal splunk component so I can't reinstall it like app

ps

Splunk server 5.02 is running under windows

Tags (1)
0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

You have the one of the TA-SQLServer technology add-ons on your server. This contains the dm_audit_class_type lookup as an automated lookup.

You have two choices:
1) Edit the props.conf in the TA-SQLServer that you have installed to remove the automatic lookup.
2) Export the lookup table in the TA-SQLServer that you have installed to remove the warning.

Either is a good approach. Note that the new Splunk for SQL Server beta opts for option #1.

lguinn2
Legend

I would check to see if a lookup table with that name exists - and if it does, then I would make sure that its permissions are properly set.

Second, I might reinstall the Splunk for Windows app.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...