My splunk show the following message suddenly but I don know how to solve it. I tried to search 'ns_log' and 'ns_msg_lookup' but cannot find it. Please advice. Thanks
The lookup table 'ns_msg_lookup' does not exist. It is referenced by configuration 'ns_log'.
[subsearch]: The lookup table 'ns_msg_lookup' does not exist. It is referenced by configuration 'ns_log'.
I found this in the Citrix Netscaler app - Splunk_TA_Citrix-NetScaler
If you have admin privileges, you should see the lookup table listed in Settings > Lookups > Lookup Table Files
If you do not have admin privileges, you may not see it, if you haven't been given permissions. Contact your Splunk Admin.
If you are the admin, see if any new automatic lookups have been set and disable them.
check the permission of your user, maybe you haven't the correct grants to the lookup.
Bye.
Giuseppe
As i mentioned, I cannot find those lookup table
Is the lookup listed in Settings > Lookups > Lookup Table Files?
go in your $SPLUNK_HOME/etc/apps/yourapp/metadata/ and search in file local.meta the name of your lookup, you should find the lookup.
If you don't find it in yourapp directory search it in other apps.
Bye.
Giuseppe