Splunk Search

Why did the lookup file not move despite changing its read perms?

sarahafrin
Explorer

I changed the permissions on a lookup file from the UI via Manage Apps - > Search and Reporting -> View Objects -> Read access to everyone on the lookup object. However, on my search head the lookup file is still under $SPLUNK_HOME/etc/users//search/lookups and not under $SPLUNK_HOME/etc/apps/search/lookups/. The read access has been given on app level but at the backend, the file still remains in the user directory. rendering it inaccessible. Is this a bug with Splunk?

0 Karma

cmerriman
Super Champion

I have noticed this as well, actually! I am not sure why it does that, exactly, but my best suggestion would be to submit a ticket to Splunk. That's what I did 🙂 Maybe it'll be fixed in a new release.

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...