Splunk Enterprise Security

Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'

edwardrose
Contributor

On my Enterprise Security search head I am getting the following errors:

[splk-idx-01.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-01.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
[splk-idx-02.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-02.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.
[splk-idx-03.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:proactive' and lookup table 'sep_action_lookup'.
[splk-idx-03.wv.mentorg.com] Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'sep:risk' and lookup table 'sep_action_lookup'.

We added the TA-sepapp12 to the search head and these errors started after that. Previously we had only added the TA-sep addon and we were not seeing all the correct lookups. After we added the TA-sepapp12 to the ES search head we started seeing items fill up in the dashboards that address SEP/Virus/Malware in ES.

So how do I fix the errors now in the ES search area?

thanks
ed

0 Karma
1 Solution

edwardrose
Contributor

Moved the TA-sep to disabled apps.

We had multiple lookup definitions looking at the same file. Both TA-sepapp12 and TA-sep had lookup definitions looking at sep_actions.csv. once we removed TA-sep and consolidated to TA-sepap12 issue was resolved.

View solution in original post

edwardrose
Contributor

Moved the TA-sep to disabled apps.

We had multiple lookup definitions looking at the same file. Both TA-sepapp12 and TA-sep had lookup definitions looking at sep_actions.csv. once we removed TA-sep and consolidated to TA-sepap12 issue was resolved.

Get Updates on the Splunk Community!

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...