Splunk Search

Why did the lookup file not move despite changing its read perms?

sarahafrin
Explorer

I changed the permissions on a lookup file from the UI via Manage Apps - > Search and Reporting -> View Objects -> Read access to everyone on the lookup object. However, on my search head the lookup file is still under $SPLUNK_HOME/etc/users//search/lookups and not under $SPLUNK_HOME/etc/apps/search/lookups/. The read access has been given on app level but at the backend, the file still remains in the user directory. rendering it inaccessible. Is this a bug with Splunk?

0 Karma

cmerriman
Super Champion

I have noticed this as well, actually! I am not sure why it does that, exactly, but my best suggestion would be to submit a ticket to Splunk. That's what I did 🙂 Maybe it'll be fixed in a new release.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Observability - October 2025

What’s New?  We’re excited to announce the latest enhancements to Splunk Observability Cloud and share what’s ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened Audit Trail v2 wasn’t written in isolation—it was shaped by your voices. In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...