Hi,
Distributed deployment that includes SH Cluster and IDX Cluster, HEC on IDXs is used to receive the data.
I want to use ingest time lookups BUT the lookup will need to be refreshed (let's say hourly).
Now the question is how will that work?
SHs can refresh a lookup and it will be pushed as part of the search bundle to the IDXs, but I don't think IDXs will know how to use it for ingest time lookup (as this bundle is used during search time), would they?
The only option I can think of is to run the scheduled search that populates the lookup on Cluster Master but tell it to output the lookup into the `slave_apps` folder, but that will require to push a new IDX bundle every time.....
Any thoughts on how to do it?
Thanks.