Hi there,
I am getting "The lookup table 'windows_action_lookup' does not exist. It is referenced by configuration 'source::*:Security'." and 'source::WinEventLog:Security|host::mydc|WinEventLog:Security'
I have checked my lookups via the Splunk GUI and cannot find any reference to these?
AKA, I don't have any duplicates, as mentioned here.
do you have Splunk for Windows? which version? I think Splunk for Windows 4.5.1 fixed this issue.
Version 4.5.1 (current version - updated Mar 09, 2012)
release notes:
Fixed bug with Windows app lookups being unavailable to other Splunk applications.