All Apps and Add-ons

Splunk for Symantec: Why am I getting messages "The lookup table 'networkservice' does not exist. It is referenced by configuration 'cisco:..."?

jwalzerpitt
Influencer

Has anyone else seen these messages in the Splunk for Symantec app:

The lookup table 'networkservice' does not exist. It is referenced by configuration 'cisco:asa.
The lookup table 'networkservice' does not exist. It is referenced by configuration 'cisco:fwsm'.
The lookup table 'networkservice' does not exist. It is referenced by configuration 'cisco:pix'.

Trying to figure out how/where these lookup table calls are invoked so I can suppress them.

Thx

tskinnerivsec
Contributor

I'm troubleshooting the same isssue. In my case they are coming from SA-cisco-asa, but when searching through AV data, no fields in the search results should trigger the search results. I tried editing permissions, etc. I thought this was due to the fact that I'm using a limited user that only has access to the AV index and nothing else. I do not see these issues arise with an admin user that has more rights in my Splunk installation, I only witness this with a user account that is limited to the one search index.

0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...