Splunk Search

Why am I unable to search uploaded lookup tables on SHC?

jking81
Engager
I’m receiving an error whenever I try to view any csv lookup tables I have uploaded into my search head cluster (v8.1.6).   Uploading the same csv files on to my local sandbox works without issue.  
 
With the query

 

| inputlookup <filename>.csv

 

I receive the error

 

The lookup table '<filename>.csv' requires a .csv or KV store lookup definition.

 

The .csv files appear on the local file system and propagate across the cluster properly.  The splunkd.log also doesn't give any information beyond what the UI already outputs.

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Could it be permissions? Can you see the lookup file in the lookups list? Is it private/app/global permission?

Did you create the lookup from the Add new lookup in the UI - what was the destination app?

 

0 Karma

Gr0und_Z3r0
Contributor

hi @jking81 

In addition to creating a lookup table by uploading the file, you'll also need to create a definition.
Under lookups, check for lookup definition option, select and configure it with the uploaded file and other field details as necessary. Once configured you should be able to search the content from the lookup file.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...