mbegan / Okta-Identity-Cloud-for-Splunk

Public REPO for splunkbase app
https://splunkbase.splunk.com/app/3682/
Other
19 stars 13 forks source link

Could not load lookup=LOOKUP-event_type_lookup #37

Closed MartijnSF closed 3 years ago

MartijnSF commented 3 years ago

After upgrading from 2.25.19 to the new 2.25.21 release we are getting this error every search.

Could not load lookup=LOOKUP-event_type_lookup

It looks like an automatic lookup fails.

Splunk Cloud 8.2.2107.1.

Thanks in advance! Martijn

s-m-p commented 3 years ago

Is the lookup definition exported to your app context? Do you have permission to read the app, lookup definition and lookup file?

On Fri, Oct 15, 2021 at 10:58 MartijnSF @.***> wrote:

After upgrading from 2.25.19 to the new 2.25.21 release we are getting this error every search.

Could not load lookup=LOOKUP-event_type_lookup

It looks like an automatic lookup fails.

Thanks in advance! Martijn

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/mbegan/Okta-Identity-Cloud-for-Splunk/issues/37, or unsubscribe https://github.com/notifications/unsubscribe-auth/AJGWHFB4HM5OWGCYY3SKI63UHBFSPANCNFSM5GCIY5EA . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.

MartijnSF commented 3 years ago

It's solved by Splunk support.

They closed the ticket with the following note:

_This issue was caused by the fact that the Splunk could not load the lookup file LOOKUP-event_type_lookup, due to not finding destination field changetype. It seems the upgrade was not done successfully and the file was not updated with the new definition.