It turned out to be I have */bin/* directory in replication blacklist of distsearch.conf in the search cluster. The user_account_control_property lookup happened to be an external type (a python script under Splunk_windows_TA/bin directory). After removing this entry, the, the error went away. I also replaced the windows_apps.csv lookup under Exchange app with the one under windows_TA to get rid of the "Could not load lookup=LOOKUP-app4_for_windows_security" error.
... View more