Splunk Search

Why am I unable to search uploaded lookup tables on SHC?

jking81
Engager
I’m receiving an error whenever I try to view any csv lookup tables I have uploaded into my search head cluster (v8.1.6).   Uploading the same csv files on to my local sandbox works without issue.  
 
With the query

 

| inputlookup <filename>.csv

 

I receive the error

 

The lookup table '<filename>.csv' requires a .csv or KV store lookup definition.

 

The .csv files appear on the local file system and propagate across the cluster properly.  The splunkd.log also doesn't give any information beyond what the UI already outputs.

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Could it be permissions? Can you see the lookup file in the lookups list? Is it private/app/global permission?

Did you create the lookup from the Add new lookup in the UI - what was the destination app?

 

0 Karma

Gr0und_Z3r0
Contributor

hi @jking81 

In addition to creating a lookup table by uploading the file, you'll also need to create a definition.
Under lookups, check for lookup definition option, select and configure it with the uploaded file and other field details as necessary. Once configured you should be able to search the content from the lookup file.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...