Splunk Search

help on could not load lookup message

jip31
Motivator

Hello

When I run a search i have the message "could not load lookup" with different lookup name

For example :

Could not load lookup=LOOKUP-Kerberosfailurecode

Could not load lookup=LOOKUP-Kerberosresultcode

Could not load lookup=LOOKUP-syscall

I had a look in the lookup definition menu and I can see that some lookup are referenced to my splunk apps even if i dont use these lookups in my apps!

But i can change the name of the apps

Is it possible to change it?

Moreover, some lookup like "syscall" doesnt exists in my lookup definition menu

so how to solve this issue please?

 

Tags (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

This probably means that they are defined as automatic lookups, so will always be executed if the matching conditions are true for that lookup definition, e.g. it is the correct sourcetype.

The fact that it is failing could be that you don't have permissions to see some part of the lookup or that the lookup is not present and the definition is trying to refer to a non existent lookup, or that the automatic lookup definition is wrong. For example you can cause this problem by creating a field in the automatic lookup that does not exist in the lookup file and you will get this message.

Do you have a Splunk sys admin - they should look at this to find out what is wrong with the automatic lookup.

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

This probably means that they are defined as automatic lookups, so will always be executed if the matching conditions are true for that lookup definition, e.g. it is the correct sourcetype.

The fact that it is failing could be that you don't have permissions to see some part of the lookup or that the lookup is not present and the definition is trying to refer to a non existent lookup, or that the automatic lookup definition is wrong. For example you can cause this problem by creating a field in the automatic lookup that does not exist in the lookup file and you will get this message.

Do you have a Splunk sys admin - they should look at this to find out what is wrong with the automatic lookup.

0 Karma

jip31
Motivator

Thanks

No sys admin unfortunately

So im going to try to correct it...

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...