Splunk Search

The lookup table 'windows_action_lookup' does not exist. It is referenced by configuration 'source::*:Security'.

derekleuridan
New Member

Hi there,

I am getting "The lookup table 'windows_action_lookup' does not exist. It is referenced by configuration 'source::*:Security'." and 'source::WinEventLog:Security|host::mydc|WinEventLog:Security'

I have checked my lookups via the Splunk GUI and cannot find any reference to these?

AKA, I don't have any duplicates, as mentioned here.

Tags (2)
0 Karma

MarioM
Motivator

do you have Splunk for Windows? which version? I think Splunk for Windows 4.5.1 fixed this issue.

Splunk App for Windows

Version 4.5.1 (current version - updated Mar 09, 2012)

release notes:

Fixed bug with Windows app lookups being unavailable to other Splunk applications.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...