Reporting

error while creating a pivot in splunk 6 tutorial

Radu3000
Engager

I am new to splunk. After installing it I have tried the Splunk-6.0-PivotTutoria.pdf - upto this point:

  1. Select "Purchase Requests". This opens a New Pivot editor for the Purchase Requests object.

But then I am getting this error:

The search job has failed due to an
error. You may be able view the job in
the Job Inspector. Share Export Print
Open in Search Starting job... Error
in 'lookup' command: Could not find
all of the specified destination
fields in the lookup table.

Can you please help.

thanks,
Radu

Tags (3)
0 Karma

mattness
Splunk Employee
Splunk Employee

Looks like you may have defined your lookup attributes incorrectly. Go back to Part 4 of the tutorial and check to make sure that you have added your lookup attributes correctly in the "Edit attributes list" topic. When you set up the lookup attribute you should always click Preview to ensure that it is adding the Price and ProductName fields to your data. If it isn't, you have some troubleshooting to do. The first troubleshooting step you should take to is make sure that the price_lookup has been correctly set up, which you do here.

mattness
Splunk Employee
Splunk Employee

The easiest thing to do in that case might be to just use the Send Feedback button at the bottom of the Data Model Tutorial topics that had discrepancies.

Radu3000
Engager

Thanks for your answer - I have moved a bit further (had to basically restart) through the tutorial - but got stuck on charts section.

The tutorial gives an idea what and how it can be accomplished... for a user that has splunk experience already. However it lacks accuracy in a few places - and a novice would always go back to support. Can you please improve it? I can provide the discrepancies - offline.

Thanks,
Radu

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...