We recently upgraded the PAN app in our splunk instances. It's now complaining that it can't find a couple different lookup tables: flowintegrator and port_lookup
Every time you run a search on the pan_log index this message shows up: Error 'Could not find all of the specified lookup fields in the lookup table.' for conf 'flowintegrator' and lookup table 'port_lookup'.
There doesn't seem to be any obvious way to create this lookups and it's not mentioned in the install documents (that I've found).
We're not even using the flowintegrator option.