Splunk Search

Why am I getting no results found when creating and searching my field lookups?

sushmitha_mj
Communicator

I used this document to create my lookup table and define fields
http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchTutorial/Usefieldlookups

Then I saw how to search on the document below
http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchTutorial/Searchwithfieldlookups

But I get no results found. I went through the steps several times. Why would it be ?

Tags (2)
0 Karma
1 Solution

sundareshr
Legend

Start with typing |inputlookup lookupfilename to see if you get any results. If you don't its probably a permissions issue. Check permissions for lookup table AND lookup definition (global vs app vs private).

If you do get results back, Verify values in the lookup file and values in index are identical (case, spelling etc)

View solution in original post

sundareshr
Legend

Start with typing |inputlookup lookupfilename to see if you get any results. If you don't its probably a permissions issue. Check permissions for lookup table AND lookup definition (global vs app vs private).

If you do get results back, Verify values in the lookup file and values in index are identical (case, spelling etc)

aaraneta_splunk
Splunk Employee
Splunk Employee

Hello @sushmitha_mj - Without knowing any more information about your current situation, it could have something to do with your lookup table file or your sharing permissions or even the search you’re trying to perform. It would be helpful to share more information in a comment below. The more information you provide to the Answers community, the greater chance that you’ll be able to get some help. Thank you 🙂

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...