Splunk Search

[hdfsprovider] Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table

dannili
Communicator

Hi all, I have a CSV lookup file to map with one field in my indexed data. The search was working perfectly before, but today, my search returned 0 results with this alert:

[hdfsprovider] Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.

This is my search:

 index=skype_session  | rex "FromIPAddr\"\"\:\"\"(?<FromIPAddr>[^\"]+)\"\"\,\"\"ToIPAddr\"\"" |  rex "ToIPAddr\"\"\:\"\"(?<ToIPAddr>[^\"]+)\"\"\,\"\"FromBssid\"\""    | rex "MediaStartTime\"\"\:\"\"(?<MediaStartTime>[^\"]+)\." | rex "MediaEndTime\"\"\:\"\"(?<MediaEndTime>[^\"]+)\." |  rex "(?<FromUri>[a-zA-Z0-9_\-\.]+@[a-zA-Z0-9_\-\.]+\.[a-zA-Z]{2,5})\",\"(?<ToUri>[a-zA-Z0-9_\-\.]+@[a-zA-Z0-9_\-\.]+\.[a-zA-Z]{2,5})" | 
    lookup staff.csv email AS FromUri  | dedup FromUri |  where FromIPAddr!="" | stats count by department | sort - count

staff.csv looks like this (denoted with comma UTF-8): I wanted to check if indexed field FromUri exists in an email field in the lookup, and if yes, output the department field in the lookup.

|email|department|
|--------|-----------------|
|--------|-----------------|
I checked other questions and there are some stating maybe the Splunk version and .conf issues. But I didn't change .conf and my Splunk version is 6.5.2.

Does anyone know how to solve this? Thanks!

0 Karma

bhavikbhalodia
Path Finder

Hi Dannili,

Check this thing with the use of KV store lookup, you might get your answer.

Thanks,
Bhavik

0 Karma

vnravikumar
Champion
0 Karma

dannili
Communicator

Thanks for your comment but the problem remains. I have checked the file and there are no hidden chars. Any other suggestions?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...