Splunk Search

Lookups within a search head pool not finding shared storage lookup table

willthames2
Path Finder

I can replicate this behaviour within a search head pool by

  • Add a Lookup Table, and upload a CSV file
  • Change permissions to be App
  • Note that location is now <sharedstorage>/etc/apps/<app>/lookups/<csvfile> (and not <splunkroot>/etc/apps/<app>/lookups/<csvfile>
  • Try to add a lookup definition, but the lookup table is not in the dropdown
  • If I add the lookup table to the <splunkroot>/etc/apps/<app>/lookups/<csvfile>, I can add the lookup definition

What I need is for the lookup definition dropdown to be able to find lookup tables under <sharedstorage>/etc/apps/<app>/lookups/<csvfile>

1 Solution

ewoo
Splunk Employee
Splunk Employee

From which app are you using Manager?

One "wrinkle" to the UI -- the dropdown of available lookup table files is based on the app context of Manager, not the destination app you choose for the lookup definition.

In other words, if you are using Manager from the Home app while writing these lookup table files and definitions to the "search" app via the "destination app" dropdowns, then this is expected (though somewhat confusing) behavior.

The workaround is to use Manager from the search app or to share the lookup table globally (across all apps).

View solution in original post

ewoo
Splunk Employee
Splunk Employee

From which app are you using Manager?

One "wrinkle" to the UI -- the dropdown of available lookup table files is based on the app context of Manager, not the destination app you choose for the lookup definition.

In other words, if you are using Manager from the Home app while writing these lookup table files and definitions to the "search" app via the "destination app" dropdowns, then this is expected (though somewhat confusing) behavior.

The workaround is to use Manager from the search app or to share the lookup table globally (across all apps).

willthames2
Path Finder

That is confusing behaviour! Thanks for the explanation!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...