Splunk Search

Lookups within a search head pool not finding shared storage lookup table

willthames2
Path Finder

I can replicate this behaviour within a search head pool by

  • Add a Lookup Table, and upload a CSV file
  • Change permissions to be App
  • Note that location is now <sharedstorage>/etc/apps/<app>/lookups/<csvfile> (and not <splunkroot>/etc/apps/<app>/lookups/<csvfile>
  • Try to add a lookup definition, but the lookup table is not in the dropdown
  • If I add the lookup table to the <splunkroot>/etc/apps/<app>/lookups/<csvfile>, I can add the lookup definition

What I need is for the lookup definition dropdown to be able to find lookup tables under <sharedstorage>/etc/apps/<app>/lookups/<csvfile>

1 Solution

ewoo
Splunk Employee
Splunk Employee

From which app are you using Manager?

One "wrinkle" to the UI -- the dropdown of available lookup table files is based on the app context of Manager, not the destination app you choose for the lookup definition.

In other words, if you are using Manager from the Home app while writing these lookup table files and definitions to the "search" app via the "destination app" dropdowns, then this is expected (though somewhat confusing) behavior.

The workaround is to use Manager from the search app or to share the lookup table globally (across all apps).

View solution in original post

ewoo
Splunk Employee
Splunk Employee

From which app are you using Manager?

One "wrinkle" to the UI -- the dropdown of available lookup table files is based on the app context of Manager, not the destination app you choose for the lookup definition.

In other words, if you are using Manager from the Home app while writing these lookup table files and definitions to the "search" app via the "destination app" dropdowns, then this is expected (though somewhat confusing) behavior.

The workaround is to use Manager from the search app or to share the lookup table globally (across all apps).

willthames2
Path Finder

That is confusing behaviour! Thanks for the explanation!

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...