Splunk Search

Why am I unable to search uploaded lookup tables on SHC?

jking81
Engager
I’m receiving an error whenever I try to view any csv lookup tables I have uploaded into my search head cluster (v8.1.6).   Uploading the same csv files on to my local sandbox works without issue.  
 
With the query

 

| inputlookup <filename>.csv

 

I receive the error

 

The lookup table '<filename>.csv' requires a .csv or KV store lookup definition.

 

The .csv files appear on the local file system and propagate across the cluster properly.  The splunkd.log also doesn't give any information beyond what the UI already outputs.

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Could it be permissions? Can you see the lookup file in the lookups list? Is it private/app/global permission?

Did you create the lookup from the Add new lookup in the UI - what was the destination app?

 

0 Karma

Gr0und_Z3r0
Contributor

hi @jking81 

In addition to creating a lookup table by uploading the file, you'll also need to create a definition.
Under lookups, check for lookup definition option, select and configure it with the uploaded file and other field details as necessary. Once configured you should be able to search the content from the lookup file.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...