Splunk Search

Why does my query not find values in the lookup table sometimes when they do in fact exist in the lookup table??

hanacurtis
New Member

I have several csv lookup tables that are nightly updated by a scheduled report when no one is using the system. The report consists of a dbx query that queries our mySQL database and then uses outputlook to write the data to the lookup csv file. This seems to be working fine.

The problem is that queries that use the lookup tables sometimes cannot find the values in the lookup table even though they are present ( i can find the values using inputlookup).

We have several queries in various dashboards that use the lookups. Sometimes, the first time the query is run, the values are not found but if the query is run again, the values are found. I have also found that looking at the lookup table directly ( by using inputlookup) sometimes does not find any data, but rerunning the query then does find the data.

I have not been able to identify a consistent pattern. It seems that the issue occurs first time queries are run after the lookup table has been updated overnight but that's not consistent either.

thanks for you help

Using Splunk 7.1.1

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...