I recently upgraded our Splunk Enterprise deployment up to 7.2.7 and Palo Alto Networks App to 6.1.1 and the Add-on to 6.1.1. I now receive the messages on the search head cluster members:
Could not load lookup=LOOKUP-minemeldfeeds_dest_lookup
Could not load lookup=LOOKUP-minemeldfeeds_src_lookup
I've looked through all the answers from previous threads and none of them fix the issue.
Thanks.
We got something similar when we disabled the KVStore. Do you have that enable or disabled?