Splunk Search

Why am I getting no results found when creating and searching my field lookups?

sushmitha_mj
Communicator

I used this document to create my lookup table and define fields
http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchTutorial/Usefieldlookups

Then I saw how to search on the document below
http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchTutorial/Searchwithfieldlookups

But I get no results found. I went through the steps several times. Why would it be ?

Tags (2)
0 Karma
1 Solution

sundareshr
Legend

Start with typing |inputlookup lookupfilename to see if you get any results. If you don't its probably a permissions issue. Check permissions for lookup table AND lookup definition (global vs app vs private).

If you do get results back, Verify values in the lookup file and values in index are identical (case, spelling etc)

View solution in original post

sundareshr
Legend

Start with typing |inputlookup lookupfilename to see if you get any results. If you don't its probably a permissions issue. Check permissions for lookup table AND lookup definition (global vs app vs private).

If you do get results back, Verify values in the lookup file and values in index are identical (case, spelling etc)

aaraneta_splunk
Splunk Employee
Splunk Employee

Hello @sushmitha_mj - Without knowing any more information about your current situation, it could have something to do with your lookup table file or your sharing permissions or even the search you’re trying to perform. It would be helpful to share more information in a comment below. The more information you provide to the Answers community, the greater chance that you’ll be able to get some help. Thank you 🙂

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...