All Apps and Add-ons

Could not load lookup=LOOKUP-minemeldfeeds...

Scottc_2
Engager

Palo Alto app/TA installed across search/index cluster and on ES standalone head. Ran without problems for some time, but now we're seeing errors on the search cluster for ANY search in Splunk. Two errors per indexer:

  • Could not load lookup=LOOKUP-minemeldfeeds_dest_lookup
  • Could not load lookup=LOOKUP-minemeldfeeds_src_lookup

Can anyone point me in the right direction for a solution to this? I've been digging and can't find an obvious reason for the error.

Thanks.

0 Karma
1 Solution

Scottc_2
Engager

The solution for this ended up being a search head out of sync with the rest of the cluster. Once I resolved the sync issue, the error disappeared.

Thanks to the others for your responses.

View solution in original post

0 Karma

Scottc_2
Engager

The solution for this ended up being a search head out of sync with the rest of the cluster. Once I resolved the sync issue, the error disappeared.

Thanks to the others for your responses.

0 Karma

woodcock
Esteemed Legend

Sweet. Click Accept on your answer to close the question.

0 Karma

lakshman239
Influencer

I believe this came up when https://splunkbase.splunk.com/app/2757/ version 6.0.0 introduced Mime, which broke the props/transforms.conf. This has since been fixed in later versions. we use 6.0.2 with no issues now and also an updated version 6.1.x

woodcock
Esteemed Legend

You must add it in the right place. Go to Settings -> Lookups -> Lookup Definitions and search for the reported lookup ( minemeldfeeds_dest_lookup ). There you will see the name of the lookup file being used and the app which should own it. Create/replace the lookup file with the same name in that app and the error will go away.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...