<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Distributed Architecture in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749492#M11997</link>
    <description>&lt;P&gt;&lt;SPAN&gt;We are storing data in a Splunk lookup file on one of the forwarders.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;In our distributed Splunk architecture, this lookup data is not getting forwarded to the indexers or the search head, and therefore it is not available for search or enrichment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;How can we sync or transfer this lookup data from the forwarder to the search head (or indexers) so that it can be used across the distributed environment?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jul 2025 11:44:04 GMT</pubDate>
    <dc:creator>gurunagasimha</dc:creator>
    <dc:date>2025-07-09T11:44:04Z</dc:date>
    <item>
      <title>Splunk Distributed Architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749491#M11993</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are storing data in a Splunk lookup file on one of the forwarders.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;In our distributed Splunk architecture, this lookup data is not getting forwarded to the indexers or the search head, and therefore it is not available for search or enrichment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;How can we sync or transfer this lookup data from the forwarder to the search head (or indexers) so that it can be used across the distributed environment?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 11:40:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749491#M11993</guid>
      <dc:creator>gurunagasimha</dc:creator>
      <dc:date>2025-07-09T11:40:38Z</dc:date>
    </item>
    <item>
      <title>Splunk Distributed Architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749492#M11997</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are storing data in a Splunk lookup file on one of the forwarders.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;In our distributed Splunk architecture, this lookup data is not getting forwarded to the indexers or the search head, and therefore it is not available for search or enrichment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;How can we sync or transfer this lookup data from the forwarder to the search head (or indexers) so that it can be used across the distributed environment?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 11:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749492#M11997</guid>
      <dc:creator>gurunagasimha</dc:creator>
      <dc:date>2025-07-09T11:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed Architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749495#M11994</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266853"&gt;@gurunagasimha&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the lookup, I suppose, comes from a csv or txt file, so read this file on the Forwarder and store it on an index or a lookup on the Indexers o Search Head so yu can use it.&lt;/P&gt;&lt;P&gt;How to do it: create on the Forwarder a file input that reads the csv file.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 11:49:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749495#M11994</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-07-09T11:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed Architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749496#M11998</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266853"&gt;@gurunagasimha&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;why did you create two identical questions?&lt;/P&gt;&lt;P&gt;Anyway, see my answer in the question&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749491#M11993" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749491#M11993&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 11:51:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749496#M11998</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-07-09T11:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed Architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749500#M11995</link>
      <description>&lt;P&gt;Lookup format is kvstore. We are ingesting the data through scripts and storing it in lookups in the Splunk forwarder. We are using a heavy forwarder.&lt;/P&gt;&lt;P&gt;Is there any other way to automatically sync in the lookups?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 12:17:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749500#M11995</guid>
      <dc:creator>gurunagasimha</dc:creator>
      <dc:date>2025-07-09T12:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed Architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749501#M11996</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266853"&gt;@gurunagasimha&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Lookup files on forwarders are not automatically forwarded from forwarders to indexers or search heads. To make lookup data available across your distributed environment you would need to send it somehow to your Search Head (Cluster) - there are a number of ways you could do this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) On your HF run a scheduled search using | inputlookup to load the contents of the lookup and then use the | collect command to write the contents to an index, on your SH/SHC you can create a scheduled search to load the indexed data and use | outputlookup to write it to a lookup&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2) Use a custom REST API script to copy the kvstore lookup from your HF to your SH/SHC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3) Use the&amp;nbsp;KV Store Tools Redux app (&lt;A href="https://splunkbase.splunk.com/app/5328" target="_blank"&gt;https://splunkbase.splunk.com/app/5328&lt;/A&gt;) to upload from the HF to SHC&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 12:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749501#M11996</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-09T12:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed Architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749560#M11999</link>
      <description>&lt;P&gt;Merged both threads.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 11:31:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749560#M11999</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-07-10T11:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed Architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749785#M12000</link>
      <description>How you are creating those kvstore lookups in HF? What is the reason to use kvstore instead of csv file or modular input to send those directly into indexers?</description>
      <pubDate>Mon, 14 Jul 2025 21:34:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749785#M12000</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-07-14T21:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed Architecture</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749812#M12001</link>
      <description>&lt;P&gt;To use a lookup to enrich a search, the lookup needs to exist as a lookup on the Search Head&lt;BR /&gt;A lookup on a heavy forwarder is not going to be available at search time.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What you need to do is get a copy of the lookup on the SH.&lt;BR /&gt;&lt;BR /&gt;The easiest (imo) option is to index the lookup file on the HF - simply define it as an input on the HF and have Splunk monitor it for changes. You can send this to any index, but lets assume you create and use one called "lookups_index" and sourcetype "my_hf_lookup"&lt;BR /&gt;&lt;BR /&gt;On your search head, you can now create a lookup-generating search:&lt;BR /&gt;Depending on what your lookup contains (dates, product_ids, error codes) you would create a search like:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=lookups_index soucetype=my_hf_lookup 
|dedup product_code 
|table product_code product_description product_price
|outputlookup my_sh_lookup.csv&lt;/LI-CODE&gt;&lt;P&gt;I like to name these something like: "&lt;EM&gt;LOOKUPGEN-my_sh_lookup.csv&lt;/EM&gt;"&lt;BR /&gt;&lt;BR /&gt;You can then schedule that to run once a day/week/hour (depending on your anticipated lookup change frequency)&lt;BR /&gt;&lt;BR /&gt;You can then use:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|lookup my_sh_lookup.csv product_code OUTPUT product_name product_price&lt;/LI-CODE&gt;&lt;P&gt;In your searches&lt;BR /&gt;&lt;BR /&gt;- Although I find it better practice to actually create a lookup definition and use that&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 08:16:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Splunk-Distributed-Architecture/m-p/749812#M12001</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2025-07-15T08:16:09Z</dc:date>
    </item>
  </channel>
</rss>

