A customer with a large distributed environment has blacklisted a large lookup from the search bundle to decrease the bundle size using distsearch.conf.
After this change, when running searches utilizing the lookup that was blacklisted they see error messages in the Splunk Search UI stating the lookup file does not exist.
What can the customer do to resolve the issue?
pbandj12
Highly Voted 3 years, 4 months agohpbdcb
Most Recent 1 year agojcisco123
1 year, 11 months agojugulinho
3 years, 8 months agojbabbin
4 years ago