All Apps and Add-ons

Splunk for Palo Alto Networks: Why are we getting multiple "The lookup table...does not exist" errors?

cyrillefranchet
Explorer

Hello,

We met an issue with the Splunk for Palo Alto Networks app "CSV does not exist".

Splunk works in Windows Server 2012 R2.
alt text

Could you please help us ?

Regards
Rémy

0 Karma

woodcock
Esteemed Legend

Look for a namespace collision problem. Somewhere in your configurations that you wrote/installed before you added the Palo Alto Networks app, you may have created a Knowledge Object with the exact same lookup file name or lookup definition name and given it a "global" permission (scope). If you happened to pick the same name for yours as is being used by PAN, you may be interfering with the chain of KOs within the PAN app.

0 Karma

bmacias84
Champion

Possible name collision problem. This is also cause if you are using automatic lookup in which user(s) do not have permission to the csv lookup file. Either upload/ generate a new csv lookup, remove automatic lookup, or change to the permission on the csv to everyone read.

0 Karma

woodcock
Esteemed Legend

I cannot see this being the problem because in this case, all of the configuration files in question are pre-packaged in the Palo Alto Networks app, unless some idiot modified permissions after the app was installed.

0 Karma

maciep
Champion

Are you running that search outside of the palo alto app? If so, do you get the same results if you run it inside the palo alto app? I'm wondering if maybe the lookups aren't shared globally?

Of course maybe make sure the lookups are actually there too, Settings -> Lookups -> Lookup definitions. Then choose the "Splunk for Palo Alto" app in the dropdown.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...