How can I determine:
1) Why a Lookup is working on one search head but not on another?
2) How to get it to work on the second search head.
More detail:
I've been tasked with consolidating alerts on one search head. One of the alerts boils down to whether a macro containing the Lookup "thostinfo" works. I notice that on the SH it works, it is mentioned in "Searches, Reports, and Alerts"; on the SH where it doesn't it is not listed there.
I've found https://answers.splunk.com/answers/472888/splunk-app-for-windows-infrastructure-how-to-fix-t.html and wondered if the accepted answer would work. But I barely know enough to ask what questions I should be asking.
Many thanks.
... View more