Splunk Dev

Unable to delete automatic lookup

aphextwin
New Member

Hi Folks

I've created a new lookup for Windows event 680 and applied it successfully. This morning, due to some other admin's actions the look up stopped working and troubleshooting it didnt bear any fruit.

I've decided to clear the slate and start fresh - but after removing the lookup table and definition, I am unable to remove the entry from the "Automatic Lookup" list.

Error Quoted:

*Error occurred attempting to remove '680-lookup-auto' In handler
'props-lookup': Object
'680-lookup-auto' does not
exist in user=admin, app=search:
props.conf

Checked props.conf and sure enough it's not listed. Need to have it removed as every normal search will return errors on the main page refering to the auto-lookup.

Any help would be appreciated.

Tags (1)
0 Karma

Drainy
Champion

Which props.conf have you checked?
Possible locations for it could be;

SPLUNK_HOME/etc/apps/search/local/
SPLUNK_HOME/etc/users/USERNAME/APP/local/  <- could be the search app here
SPLUNK_HOME/etc/system/local/

A nice quick way to check is to run the following command in the SPLUNK_HOME/bin directory;

Linux - ./splunk cmd btool props list --debug

Windows - splunk cmd btool props list --debug

This will list all the lines from props.conf it has read in and prefix it with the name of the app applying it.

Drainy
Champion

No problem, glad it helped 🙂 Feel free to click on the tick to the left of my answer, it will just mark this as the right answer for anyone with the same problem in the future.

0 Karma

aphextwin
New Member

thanks for that mate! the debug tool helped!
found the reference, removed it, restarted and i was able to remove it from the autolookup list.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...