<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to maintain lookups? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-maintain-lookups/m-p/414745#M4957</link>
    <description>&lt;P&gt;Splunk will let you know when the bundle size is too big, don't worry about that.  I use automatic lookups whenever they make sense; when it is useful for everybody.  If the data has a code and you can translate to a description (like HTTP response codes), then I set it up as automatic.  If it is only for me, I just do it in my search manually.  The only performance issues you may have is if you use the hacky &lt;CODE&gt;apply this to all sourcetypes&lt;/CODE&gt; thing.&lt;/P&gt;</description>
    <pubDate>Sun, 01 Jul 2018 15:21:58 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2018-07-01T15:21:58Z</dc:date>
    <item>
      <title>How to maintain lookups?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-maintain-lookups/m-p/414744#M4956</link>
      <description>&lt;P&gt;I am analyzing our Splunk set-up and was going through the lookups, need suggestions on the best strategy to maintain lookups.&lt;BR /&gt;
1. bundle size &lt;BR /&gt;
2. switching over to manual lookups(instead of automatic lookups)&lt;BR /&gt;
3. Performance issues with automatic lookups&lt;/P&gt;

&lt;P&gt;Would appreciate if something else can be analyzed or taken care of.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
SB&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jun 2018 06:18:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-maintain-lookups/m-p/414744#M4956</guid>
      <dc:creator>sidhantbhayana</dc:creator>
      <dc:date>2018-06-30T06:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to maintain lookups?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-maintain-lookups/m-p/414745#M4957</link>
      <description>&lt;P&gt;Splunk will let you know when the bundle size is too big, don't worry about that.  I use automatic lookups whenever they make sense; when it is useful for everybody.  If the data has a code and you can translate to a description (like HTTP response codes), then I set it up as automatic.  If it is only for me, I just do it in my search manually.  The only performance issues you may have is if you use the hacky &lt;CODE&gt;apply this to all sourcetypes&lt;/CODE&gt; thing.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jul 2018 15:21:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-maintain-lookups/m-p/414745#M4957</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-01T15:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to maintain lookups?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-maintain-lookups/m-p/414746#M4958</link>
      <description>&lt;P&gt;Thanks @woodcock, agree to your response! I am planning to blacklist few lookups as the bundle size has reached ~1.5GB and it kind of becomes an issue in search peers. &lt;BR /&gt;
Also, currently evaluating replacing lookups with kvstore, got to know that &lt;CODE&gt;Splunk creates a csv from the kvstore depending on the query and pushes the csv as part of bundle&lt;/CODE&gt;. &lt;/P&gt;

&lt;P&gt;Looking forward to understand how kvstore will work and would it be better to replace lookups, considering the fact that the data is incremental.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
SB&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 05:40:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-maintain-lookups/m-p/414746#M4958</guid>
      <dc:creator>sidhantbhayana</dc:creator>
      <dc:date>2018-07-02T05:40:54Z</dc:date>
    </item>
  </channel>
</rss>

