All Apps and Add-ons

Sideview Lookup Updater: Failed to move file

LarsN
Explorer

Hi,
I have the Sideview Utils 2.6.5 running Splunk on Windows.
I am interrested in Sideview Utils, mostly because of the Lookup Updater but I must say there is definitely some more "on the side".
Unfortunately I have encountered a problem when I try to use the Lookup Updater, it says:
"Could not write to file 'mac_vendor_ids.csv': Failed to move file to final destination"
I (admin) am the owner of the file 'mac_vendor_ids.csv' and have write access to the file - what else could I look for?

All the best
Lars

1 Solution

sideview
SplunkTrust
SplunkTrust

I'll look into it. So through Manager it works fine, but you had manually copied the lookup file into /lookups, and you had manually created the stanza in transforms?

I'll look into it and it can probably be fixed. There have been some funky permissions issues on windows and I suspect this is one more of the same. Until then just create your lookups through Manager and the Lookup Updater should have no problem editing them then. Thanks and sorry for the inconvenience.

View solution in original post

sideview
SplunkTrust
SplunkTrust

I'll look into it. So through Manager it works fine, but you had manually copied the lookup file into /lookups, and you had manually created the stanza in transforms?

I'll look into it and it can probably be fixed. There have been some funky permissions issues on windows and I suspect this is one more of the same. Until then just create your lookups through Manager and the Lookup Updater should have no problem editing them then. Thanks and sorry for the inconvenience.

LarsN
Explorer

I have only saved the file through Windows. The rest has been done through
Manager » Lookups - yes.

0 Karma

LarsN
Explorer

Yes, a new file uploaded via "create new" page in Manager > Lookups works.
The old file was stored trough native Windows.

Thank you for the swift cure.

Lars

0 Karma

sideview
SplunkTrust
SplunkTrust

A troubleshooting question - what happens if you create a new temporary csv file locally and upload it in the "create new" page in Manager > Lookups. Does Lookup Updater allow you to edit that file?

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...