Reporting

error while creating a pivot in splunk 6 tutorial

Radu3000
Engager

I am new to splunk. After installing it I have tried the Splunk-6.0-PivotTutoria.pdf - upto this point:

  1. Select "Purchase Requests". This opens a New Pivot editor for the Purchase Requests object.

But then I am getting this error:

The search job has failed due to an
error. You may be able view the job in
the Job Inspector. Share Export Print
Open in Search Starting job... Error
in 'lookup' command: Could not find
all of the specified destination
fields in the lookup table.

Can you please help.

thanks,
Radu

Tags (3)
0 Karma

mattness
Splunk Employee
Splunk Employee

Looks like you may have defined your lookup attributes incorrectly. Go back to Part 4 of the tutorial and check to make sure that you have added your lookup attributes correctly in the "Edit attributes list" topic. When you set up the lookup attribute you should always click Preview to ensure that it is adding the Price and ProductName fields to your data. If it isn't, you have some troubleshooting to do. The first troubleshooting step you should take to is make sure that the price_lookup has been correctly set up, which you do here.

mattness
Splunk Employee
Splunk Employee

The easiest thing to do in that case might be to just use the Send Feedback button at the bottom of the Data Model Tutorial topics that had discrepancies.

Radu3000
Engager

Thanks for your answer - I have moved a bit further (had to basically restart) through the tutorial - but got stuck on charts section.

The tutorial gives an idea what and how it can be accomplished... for a user that has splunk experience already. However it lacks accuracy in a few places - and a novice would always go back to support. Can you please improve it? I can provide the discrepancies - offline.

Thanks,
Radu

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...