Splunk Enterprise

Best Practice for Automatic Lookups

jaburke1
Path Finder

Is there a suggested size of lookup that would be the maximum size of a lookup that should be used for an automatic lookup?

Such as if your lookup exceeds more than x rows it would best not to use with an automatic lookup?

 

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm not sure there are best practices around automatic lookups.  There are some for lookups in general, however.  Monitor lookup size (in bytes) to make sure they don't cause the knowledge bundle to become too large (2GB).  Large lookups should be blocked from the bundle or converted to KVStore.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jaburke1
Path Finder

Thanks Rich! Is it a bad practice to use a KVStore for automatic lookups since they can get very large?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I wouldn't say that at all.  One of the features of KVStore is to replace large lookup files.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...