Splunk Search

Why does my query not find values in the lookup table sometimes when they do in fact exist in the lookup table??

hanacurtis
New Member

I have several csv lookup tables that are nightly updated by a scheduled report when no one is using the system. The report consists of a dbx query that queries our mySQL database and then uses outputlook to write the data to the lookup csv file. This seems to be working fine.

The problem is that queries that use the lookup tables sometimes cannot find the values in the lookup table even though they are present ( i can find the values using inputlookup).

We have several queries in various dashboards that use the lookups. Sometimes, the first time the query is run, the values are not found but if the query is run again, the values are found. I have also found that looking at the lookup table directly ( by using inputlookup) sometimes does not find any data, but rerunning the query then does find the data.

I have not been able to identify a consistent pattern. It seems that the issue occurs first time queries are run after the lookup table has been updated overnight but that's not consistent either.

thanks for you help

Using Splunk 7.1.1

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...