Splunk Search

What are lookups for INGEST_EVAL in distributed deployment?

ilya_resh
Engager

Hi,

Distributed deployment that includes SH Cluster and IDX Cluster, HEC on IDXs is used to receive the data.
I want to use ingest time lookups BUT the lookup will need to be refreshed (let's say hourly).

Now the question is how will that work?


SHs can refresh a lookup and it will be pushed as part of the search bundle to the IDXs, but I don't think IDXs will know how to use it for ingest time lookup (as this bundle is used during search time), would they?

The only option I can think of is to run the scheduled search that populates the lookup on Cluster Master but tell it to output the lookup into the `slave_apps` folder, but that will require to push a new IDX bundle every time.....

 

Any thoughts on how to do it?

Thanks.

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...