Splunk Search

Empty Lookup Tables - disable warning banner

apgersplunk
New Member

version 6

I maintain a set of csv files as lookup tables and everything works perfectly fine with one exception. If any of the files contain only a header but no data, the views that reference the collection of lookups pastes a yellow warning banner across the UI stating "Empty csv lookup file (contains only a header) for table ...".

Some of the csv files will occasionally be empty by design (header only) and I am trying to figure out how to disable these warnings. Any ideas?

Tags (3)
0 Karma

apgersplunk
New Member

Thanks for the quick reply and good pointer. I tested the logging levels associated with "lookup" and "csv" related channels with no luck. It seems that the handler would have fixed it. I made the test changes through the GUI while troubleshooting.

0 Karma

MuS
Legend

Hi apgersplunk,

you can either set it in log.cfg or in the Manager - System Settings - System logging and change the setting for one of the lookup channels. Available channels are:

  • LookupOperator
  • LookupTableConfPathMapper
  • LookupTablesHandler

hope this helps ...

cheers, MuS

MuS
Legend

another thought just came up my head...you can disable/modify the message bar in the XML of your views as well ..... but, this is dangerzone, because you can set it to be too strict and you will also NOT receive any other message as well (like license violations)

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...