Splunk Search

Why can't I delete lookup table files?



As an admin, I tried to delete a lookup table file. I had copied all the apps back to the search head cluster deployer, including the lookup tables files for all the apps and then pushed the updated bundle, to get the deployer back into a current state.

In doing so, I apparently made the lookup tables not able to be deleted as the option no longer appears.

So I tried to use curl to delete them but that fails to with

Object id=LookupName.csv cannot be deleted in config=lookups
  1. How can I delete these so they can be re-added?
  2. Should I not sync them to the deployer? Wouldn't they get deleted with a bundle push if they aren't there?

Thanks for the assistance!


Hi @tkw03 ,

Did you find any solution for your problem?


0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!