Getting Data In

Receiving error that “could not load lookup xxx” when using Splunk API to call report, but no such lookup files

Zane
Loves-to-Learn

hi

i got a weird problem when i call Splunk API'https://localhost:8089/servicesNS/-/search/search/jobs?output_mode=json', and i can get reaults from it, but i get such error message,  however, there is no such lookup files in my report search, and I also can NOT find these lookup in my Splunk.

is there someone can help me point out the problem? why i get this error? how can i fix it?

thanks a lot.

 

 

 "messages": [
        {
            "type": "ERROR",
            "text": "[Indexer_01_new,Indexer_11,Indexer_12,Indexer_13,Indexer_14,Indexer_16,Indexer_17,Indexer_18,Indexer_19,Indexer_20,Indexer_21,Indexer_22,Indexer_23,Indexer_24,Indexer_25,Indexer_26,Indexer_27,SearchHead_01] Could not load lookup=User_Account_With_AD"
        },
        {
            "type": "ERROR",
            "text": "[Indexer_01_new,Indexer_11,Indexer_12,Indexer_13,Indexer_14,Indexer_16,Indexer_17,Indexer_18,Indexer_19,Indexer_20,Indexer_21,Indexer_22,Indexer_23,Indexer_24,Indexer_25,Indexer_26,Indexer_27,SearchHead_01] Could not load lookup=Userauth_User_Account_With_AD"
        },
        {

results.png

Labels (4)
0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of Splunk APM’s and Splunk RUM’s streaming infrastructure in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...