Splunk Search

Splunk says lookup table doesn't exist, but it does

jambajuice
Communicator

Here is my transforms.conf for the lookup table in question:

[ossim_plugins] filename = ossim_plugins.csv max_matches = 1

Here is an example of one of the searches that references the lookup table:

search = sourcetype=ossim "Event received" NOT ((plugin_id>=1001 AND plugin_id<=1131) OR plugin_id=1597) | lookup ossim_plugins plugin_id OUTPUT plugin_name | timechart count by plugin_name

But Splunk is occasionally throwing the following error:

The lookup table 'ossim_plugins' does not exist. It is referenced by configuration 'ossim_plugins'.

The lookup table ossim_plugins.csv is located in the lookups directory of the app that the searches and dashboards are defined in.

Any ideas?

Thx.

Tags (1)

jambajuice
Communicator

Never mind... Somehow an entry was made in props.conf with the title [ossim_plugins] and the content of the stanza was garbled.

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...