I'm brand new to splunk and ran across your question while I was trying to solve the same issue....here is the query that I got to finally work . You should try using the actual name of the csv file and see if it works - that seems to be the only difference between our searches:
host=web_application sourcetype=access_combined_wcookie status=200 file=success.do | lookup products.csv productId as productId OUTPUT product_name as ProductName
this also works (adding in index=main)
index=main host=web_application sourcetype=access_combined_wcookie status=200 file=success.do | lookup products.csv productId as productId OUTPUT product_name as ProductName
I did have a similar issue to you at first. I did end up going through the whole thing again, maybe you missed a step: try going to settings | lookups | [lookup definitions] and make sure you have a similar entry to this:
product_lookup file productId,product_name,categoryId,price,Code products.csv [username] search
Thanks for posting your question, it was helpful to me to see your search string. I also went back and rewatched the video and followed along. In retrospect, it would have been way more useful to follow along with the labs WHILE watching the video.
... View more