Splunk Search

Why am I unable to search uploaded lookup tables on SHC?

jking81
Engager
I’m receiving an error whenever I try to view any csv lookup tables I have uploaded into my search head cluster (v8.1.6).   Uploading the same csv files on to my local sandbox works without issue.  
 
With the query

 

| inputlookup <filename>.csv

 

I receive the error

 

The lookup table '<filename>.csv' requires a .csv or KV store lookup definition.

 

The .csv files appear on the local file system and propagate across the cluster properly.  The splunkd.log also doesn't give any information beyond what the UI already outputs.

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Could it be permissions? Can you see the lookup file in the lookups list? Is it private/app/global permission?

Did you create the lookup from the Add new lookup in the UI - what was the destination app?

 

0 Karma

Gr0und_Z3r0
Contributor

hi @jking81 

In addition to creating a lookup table by uploading the file, you'll also need to create a definition.
Under lookups, check for lookup definition option, select and configure it with the uploaded file and other field details as necessary. Once configured you should be able to search the content from the lookup file.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...