All Apps and Add-ons

Loading lookup file...

lukeh
Contributor

Hi 🙂

I am really impressed by this app but some larger lookup files don't load at all whereas some smaller lookup files do load ok. It gets stuck on "Loading lookup file..."

FYI: We are running Lookup File Editor 1.0 on Splunk 6.0.2

Any help would be greatly appreciated 🙂

Luke.

P.S. The lookup files do load ok in Sideview Utils Lookup Updater but your interface is cooler 😄

Tags (1)
0 Karma
1 Solution

bfernandez
Communicator

I solved this problem deleting the ownership assigned to the lookup file set in:

$SPLUNK_HOME/etc/apps/myapp/metadata/local.meta

[lookups/xxxt.csv]
version = 5.0.3
export = system
owner = name <-- delete

I hope this help

View solution in original post

bfernandez
Communicator

I solved this problem deleting the ownership assigned to the lookup file set in:

$SPLUNK_HOME/etc/apps/myapp/metadata/local.meta

[lookups/xxxt.csv]
version = 5.0.3
export = system
owner = name <-- delete

I hope this help

JensT
Communicator

Works indeed. But its a heavy limitation 😞

0 Karma

lukeh
Contributor

Thanks man!

lukeh
Contributor

no worries:
1/ Firefox 29.0.1 and Google Chrome 35.0.1916.114 m
2/ no
3/ one is 63 KB with 24 columns, and another is 1.73 MB with 2 columns

0 Karma

LukeMurphey
Champion

I'l take a look into improving this. I tested it with various browsers and lookup files and found that it reliably handled files up to 10 MB. I actually have a limit built-in so that it will show a warning if the file is too big.

Could you answer the following to help me narrow the problem down?

1) What browser are you using?
2) Are there any errors posted in the console? (in case the issue isn't related to the size of the lookup but due to some other problem)
3) How big is the lookup file?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...