Splunk 6 was installed fresh. I then copied our app from our Splunk 5 system and installed the following apps: Splunk Add-on for *Nix, Asset Discovery,
Splunk DB Connect, Splunk + OData, Sideview Utils,
S.o.S, Splunk App for Unix, Deployment Monitor, Tenable Security Center.
I swear I grepped for 'IPLookup' before I posted this question and didn't find it. This time I did find it.
The lookup was an old experiment that didn't go anywhere. I've commented it out of props.conf.
We do not see this error on our Splunk 5 system.
... View more