Splunk Search

Why am I unable to search uploaded lookup tables on SHC?

jking81
Explorer
I’m receiving an error whenever I try to view any csv lookup tables I have uploaded into my search head cluster (v8.1.6).   Uploading the same csv files on to my local sandbox works without issue.  
 
With the query

 

| inputlookup <filename>.csv

 

I receive the error

 

The lookup table '<filename>.csv' requires a .csv or KV store lookup definition.

 

The .csv files appear on the local file system and propagate across the cluster properly.  The splunkd.log also doesn't give any information beyond what the UI already outputs.

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Could it be permissions? Can you see the lookup file in the lookups list? Is it private/app/global permission?

Did you create the lookup from the Add new lookup in the UI - what was the destination app?

 

0 Karma

Gr0und_Z3r0
Contributor

hi @jking81 

In addition to creating a lookup table by uploading the file, you'll also need to create a definition.
Under lookups, check for lookup definition option, select and configure it with the uploaded file and other field details as necessary. Once configured you should be able to search the content from the lookup file.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...