Splunk Dev

Unable to delete automatic lookup

aphextwin
New Member

Hi Folks

I've created a new lookup for Windows event 680 and applied it successfully. This morning, due to some other admin's actions the look up stopped working and troubleshooting it didnt bear any fruit.

I've decided to clear the slate and start fresh - but after removing the lookup table and definition, I am unable to remove the entry from the "Automatic Lookup" list.

Error Quoted:

*Error occurred attempting to remove '680-lookup-auto' In handler
'props-lookup': Object
'680-lookup-auto' does not
exist in user=admin, app=search:
props.conf

Checked props.conf and sure enough it's not listed. Need to have it removed as every normal search will return errors on the main page refering to the auto-lookup.

Any help would be appreciated.

Tags (1)
0 Karma

Drainy
Champion

Which props.conf have you checked?
Possible locations for it could be;

SPLUNK_HOME/etc/apps/search/local/
SPLUNK_HOME/etc/users/USERNAME/APP/local/  <- could be the search app here
SPLUNK_HOME/etc/system/local/

A nice quick way to check is to run the following command in the SPLUNK_HOME/bin directory;

Linux - ./splunk cmd btool props list --debug

Windows - splunk cmd btool props list --debug

This will list all the lines from props.conf it has read in and prefix it with the name of the app applying it.

Drainy
Champion

No problem, glad it helped 🙂 Feel free to click on the tick to the left of my answer, it will just mark this as the right answer for anyone with the same problem in the future.

0 Karma

aphextwin
New Member

thanks for that mate! the debug tool helped!
found the reference, removed it, restarted and i was able to remove it from the autolookup list.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...