QuestionQ105

Search Problems

Several critical searches that were working correctly yesterday cannot locate a lookup table today. Which log file is the best place to begin troubleshooting?

  • A web_access.log
  • B btool.log
  • C configuration_change.log
  • D health.log
Explanation

Splunk tracks changes to its .conf configuration files in configuration_change.log. A lookup table’s definition and location can be controlled by configuration such as transforms.conf, so reviewing recent configuration changes is the appropriate starting point when previously working searches can no longer find the lookup.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!