<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Maximum Asset &amp;amp; Identity Lookup Size in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/507874#M8985</link>
    <description>&lt;P&gt;What is the maximum recommended size for asset/identity lookups?&lt;/P&gt;&lt;P&gt;&lt;A href="https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/assetandidentityframework/" target="_blank" rel="noopener"&gt;https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/assetandidentityframework/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've had issues with Splunk handling large numbers of assets and/or identities.&amp;nbsp; I increased the maximum bundle size to 4GB, but still had to distribute the entire huge bundle every time an identity changed.&lt;/P&gt;&lt;P&gt;Is there an option to use a KV store for assets &amp;amp; identities? Or a way to update them with a diff, rather than pushing the entire lookup?&lt;/P&gt;&lt;P&gt;Is there a memory requirement for a certain number of&amp;nbsp;assets &amp;amp; identities? Or any related performance impact for having a large number of assets &amp;amp; identities?&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jul 2020 15:48:09 GMT</pubDate>
    <dc:creator>malvidin</dc:creator>
    <dc:date>2020-07-07T15:48:09Z</dc:date>
    <item>
      <title>Maximum Asset &amp; Identity Lookup Size</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/507874#M8985</link>
      <description>&lt;P&gt;What is the maximum recommended size for asset/identity lookups?&lt;/P&gt;&lt;P&gt;&lt;A href="https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/assetandidentityframework/" target="_blank" rel="noopener"&gt;https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/assetandidentityframework/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've had issues with Splunk handling large numbers of assets and/or identities.&amp;nbsp; I increased the maximum bundle size to 4GB, but still had to distribute the entire huge bundle every time an identity changed.&lt;/P&gt;&lt;P&gt;Is there an option to use a KV store for assets &amp;amp; identities? Or a way to update them with a diff, rather than pushing the entire lookup?&lt;/P&gt;&lt;P&gt;Is there a memory requirement for a certain number of&amp;nbsp;assets &amp;amp; identities? Or any related performance impact for having a large number of assets &amp;amp; identities?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 15:48:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/507874#M8985</guid>
      <dc:creator>malvidin</dc:creator>
      <dc:date>2020-07-07T15:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Asset &amp; Identity Lookup Size</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/507885#M8986</link>
      <description>Try to keep bundle size below 1GB. Beyond that you'll have problems.&lt;BR /&gt;Blacklist the A&amp;amp;I lookups from the bundle and push them to the indexers using a different method (scp via a cron job, for example).</description>
      <pubDate>Tue, 07 Jul 2020 17:02:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/507885#M8986</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-07T17:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Asset &amp; Identity Lookup Size</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508005#M8995</link>
      <description>&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;P&gt;With large A&amp;amp;I lookups, does Splunk provide memory recommendation for acceptable performance?&lt;/P&gt;&lt;P&gt;For example, if my asset list only contains&amp;nbsp;ip&lt;SPAN&gt;,&amp;nbsp;dns,&amp;nbsp;priority,&amp;nbsp;bunit,&amp;nbsp; andcategory, how many Class A networks can I put in the lookup if the networks are 50% allocated?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 08:32:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508005#M8995</guid>
      <dc:creator>malvidin</dc:creator>
      <dc:date>2020-07-08T08:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Asset &amp; Identity Lookup Size</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508064#M8997</link>
      <description>The guidance is to keep bundle sizes below 1GB.</description>
      <pubDate>Wed, 08 Jul 2020 12:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508064#M8997</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-08T12:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Asset &amp; Identity Lookup Size</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508600#M9003</link>
      <description>&lt;P&gt;I don't know if I can stay under that size, or even under 4GB, but I understand that is the recommended limit.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 11:37:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508600#M9003</guid>
      <dc:creator>malvidin</dc:creator>
      <dc:date>2020-07-11T11:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Asset &amp; Identity Lookup Size</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508607#M9004</link>
      <description>Like I said in my first reply, if you keep large lookup files out of the bundle it will help keep the bundle size down.</description>
      <pubDate>Sat, 11 Jul 2020 12:33:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508607#M9004</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-11T12:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Asset &amp; Identity Lookup Size</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508608#M9005</link>
      <description>&lt;P&gt;Thanks for clarifying that. Can KV lookups be distributed through different channels, like scp?&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 12:37:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508608#M9005</guid>
      <dc:creator>malvidin</dc:creator>
      <dc:date>2020-07-11T12:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum Asset &amp; Identity Lookup Size</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508618#M9006</link>
      <description>KVStore collections are not included in the search bundle.</description>
      <pubDate>Sat, 11 Jul 2020 16:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maximum-Asset-amp-Identity-Lookup-Size/m-p/508618#M9006</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-11T16:49:36Z</dc:date>
    </item>
  </channel>
</rss>

