I have the very same issue, too, and I run v5.0.5. I tried updating to v5.0.9 to the same result.
Looking at Murphey's code as well as on the developer console, I extracted the URL's attempted. It seems to not be his code per se, but the backend: it's a bug with Splunk itself. The lookup editor simply fails to mask display error to the user (without viewing the console).
When you attempt to edit/view your lookup, it's running an ajax query. One of the parameters...the key parameter is owner. Remove from your query and you're golden. It's a hack, but it works around it. I myself am looking at removing that parameter from the query and it seems to work for me for now.
In lookup list view, I click on 'test.csv'. The URL I basically clicked on is:
Change it to:
Note: Luke, the two features/fixes requested are as follows:
1) If there are errors, shoot it to the page, as my page will fail and get stuck on the 'loading lookup file' splash and I'm left thinking it's still processing. Console says it had a bad request (then fails on a parameter check because there was no payload returned) which also is consistent with OP's error.
I tried uploading the snapshot, but apparently Splunk community sez I need moar karma to upload or attach links. Oh wells. Try this:
The user needs to know something's wrong. Smarter admins will be able to troubleshoot. Developer based ones (like myself, arguably) will be able to figure out precisely what to code/execute to fix.
2) Code fix: check for global permissions. Your query somewhere failed. If it's a backend Splunk issue, at least if the file is global, there's no need to specify within namespace. A slight hack, but working is better than not working.
... View more