So I'm trying to setup a search that returns the hostname of the missing forwarders to use in a BladeLogic automation job. To do so we generally run a CLI search, and use the returned rows to run a job against. Sounds easy enough.
I go into the monitoring console section, look at the forwarder deployment, and select the "missing" status link and get the query. I can filter that down to just the forwarders that are missing. Works in the GUI just fine. But when I try this from the CLI (on the same host), then query fails with this strange message.
$ /opt/splunk/bin/splunk search "| inputlookup dmc_forwarder_assets | search status=missing"
WARN: The lookup table 'dmc_forwarder_assets' is invalid.
$
Help? Anyone? Driving me c-r-a-z-y!!!
Running Splunk Enterprise v7.1
... View more