After the upgrade to 4.1.2 I started seeing this error in other app dashboards specifically my Cisco dash:
[splunkindex0] The lookup table 'app_lookup' does not exist. It is referenced by configuration 'pan_threat'.
[splunkindex0] The lookup table 'app_lookup' does not exist. It is referenced by configuration 'pan_traffic'.
[splunkindex0] The lookup table 'classification_lookup' does not exist. It is referenced by configuration 'pan_threat'.
[splunkindex0] The lookup table 'classification_lookup' does not exist. It is referenced by configuration 'pan_traffic'.
[splunkindex0] The lookup table 'pan_vendor_info_lookup' does not exist. It is referenced by configuration '(?::){0}PerfmonMk*:*'.
[splunkindex0] The lookup table 'pan_vendor_info_lookup' does not exist. It is referenced by configuration '(?::){0}XmlWinEventLog:*'.
[splunkindex0] The lookup table 'pan_vendor_info_lookup' does not exist. It is referenced by configuration '(?i)source::....zip(.\d+)?'.
[splunkindex1] The lookup table 'app_lookup' does not exist. It is referenced by configuration 'pan_threat'.
[splunkindex1] The lookup table 'app_lookup' does not exist. It is referenced by configuration 'pan_traffic'.
[splunkindex1] The lookup table 'classification_lookup' does not exist. It is referenced by configuration 'pan_threat'.
[splunkindex1] The lookup table 'classification_lookup' does not exist. It is referenced by configuration 'pan_traffic'.
[splunkindex1] The lookup table 'pan_vendor_info_lookup' does not exist. It is referenced by configuration '(?::){0}PerfmonMk*:*'.
[splunkindex1] The lookup table 'pan_vendor_info_lookup' does not exist. It is referenced by configuration '(?::){0}XmlWinEventLog:*'.
[splunkindex1] The lookup table 'pan_vendor_info_lookup' does not exist. It is referenced by configuration '(?i)source::....zip(.\d+)?'.
I thought it might be the metadata/default.meta but its unmodified.
# TODO: should these only exported to app instead of system?
# Application-level permissions
[]
access = read : [ * ], write : [ admin, power ]
### EVENT TYPES
[eventtypes]
export = system
### PROPS
[props]
export = system
### TRANSFORMS
[transforms]
export = system
[savedsearches]
export = none
[lookups]
export = none
Any ideas ?
Thanks !
,After the upgrade to 4.1.2 I started seeing the following errors in other apps :
The lookup table 'app_lookup' does not exist. It is referenced by configuration 'pan_threat'.
[splunkindex0] The lookup table 'app_lookup' does not exist. It is referenced by configuration 'pan_traffic'.
[splunkindex0] The lookup table 'classification_lookup' does not exist. It is referenced by configuration 'pan_threat'.
[splunkindex0] The lookup table 'classification_lookup' does not exist. It is referenced by configuration 'pan_traffic'.
[splunkindex0] The lookup table 'pan_vendor_info_lookup' does not exist. It is referenced by configuration '(?::){0}PerfmonMk*:*'.
These lookup files do in fact exist here: /apps/SplunkforPaloAltoNetworks/lookups/
I have a feeling this might be a metadata/default.meta problem since it was working fine before the upgrade .
default.meta
# TODO: should these only exported to app instead of system?
# Application-level permissions
[]
access = read : [ * ], write : [ admin, power ]
### EVENT TYPES
[eventtypes]
export = system
### PROPS
[props]
export = system
### TRANSFORMS
[transforms]
export = system
[savedsearches]
export = none
[lookups]
export = none
Any Ideas ?
... View more