All Apps and Add-ons

After installing the Cisco Networks App and Add-on for Splunk Enterprise 2.3.0 on Splunk 6.2, why do dashboards now show "he lookup table 'cisco_ios_facility_categories' does not exist."

molinarf
Communicator

Lookup table error: The lookup table 'cisco_ios_facility_categories' does not exist. It is referenced by configuration 'source::udp:514|host::10.32.7.7|cisco:ios'.

I upgraded to TA-Cisco_ios 2.3 and ran into this issue. With the errors that were occurring in lookup tables, I removed the app completely and then reinstalled. Both the TA and Cisco Network Apps are at version 2.3. With the IP address, it could be the switch is sending information that Splunk doesn't know how to deal with. Any ideas? I am in the process of trying to determine what the entry in the eventtypes,conf will be and what the switch is trying to send. If you can provide some insight, it would be appreciated.

0 Karma
1 Solution

mikaelbje
Motivator

Did you do a complete reinstall of TA-cisco_ios on your indexers too? Make sure the versions match on indexer and search head. As you said a complete reinstall (delete directories) and re-add apps is necessary. This has solved the exact issue you are facing for others, including myself at various customer sites.

View solution in original post

0 Karma

molinarf
Communicator

Thank you for your assistance. It is not intuitive that we should do a complete re-install and something to remember in the future. When I removed the directories for the TA-cisco_ios and the Cisco network apps and then re-installed, the issue went away.

0 Karma

mikaelbje
Motivator

Sorry about that. Some files were moved from the app to the add-on and vice versa in an previous version and that's why this happens. There's no local/default concept for the lookup directory so any old lookups are retained even when you upgrade apps.

0 Karma

mikaelbje
Motivator

Did you do a complete reinstall of TA-cisco_ios on your indexers too? Make sure the versions match on indexer and search head. As you said a complete reinstall (delete directories) and re-add apps is necessary. This has solved the exact issue you are facing for others, including myself at various customer sites.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...