<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookups slow performance in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookups-slow-performance/m-p/397847#M115451</link>
    <description>&lt;P&gt;It depends on how many definitions exist to create the field &lt;CODE&gt;guid&lt;/CODE&gt; and what types they are.  This is a VERY deep topic.  Start here and pay special attention to the parts regarding &lt;CODE&gt;lispy&lt;/CODE&gt;:&lt;BR /&gt;
&lt;A href="https://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf"&gt;https://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf&lt;/A&gt;&lt;BR /&gt;
Also check out this:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/2871/"&gt;https://splunkbase.splunk.com/app/2871/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If the field &lt;CODE&gt;guid&lt;/CODE&gt; is an indexed field, then you can use this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=my_index guid::my_guid 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Sun, 03 Mar 2019 05:14:09 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-03-03T05:14:09Z</dc:date>
    <item>
      <title>Lookups slow performance</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-slow-performance/m-p/397845#M115449</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Background&lt;/STRONG&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;We are a new SplunkCloud customer and are building out our instance, setting up our indexes, field extractions, etc. I’m currently working on Lookups and and seeing unexpected performance characteristics from the searches I am running. &lt;/LI&gt;
&lt;LI&gt;I created an automatic lookup that links the data in one of our indexes to a lookup table that has about 15k rows and 7 columns of data. The automatic lookup links the index to the lookup table via a “guid" field. &lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;This search takes 48 seconds to complete and has a scan count of 16million
&lt;CODE&gt;index=my_index guid=my_guid&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;This search takes 300ms to complete and has a scan count of 410
&lt;CODE&gt;index=my_index my_guid&lt;/CODE&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Why is the first search doing all of this extra work? We are about to roll out access to Splunk to about 150 employees. I want to make sure I understand the proper way to recommend people to run searches against this index that is linked to the lookup table.&lt;/P&gt;

&lt;P&gt;Thanks in advance,&lt;BR /&gt;
Chris&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 04:00:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-slow-performance/m-p/397845#M115449</guid>
      <dc:creator>cwinkler109</dc:creator>
      <dc:date>2019-02-26T04:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups slow performance</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-slow-performance/m-p/397846#M115450</link>
      <description>&lt;P&gt;The second search is going directly for the index to look for your guid. The first one needs to match (don't know how many fields are you matching against the lookup) every event to the lookup before filtering, and that's where this questions come into place&lt;/P&gt;

&lt;P&gt;Is that lookup CSV or KVStore based?&lt;/P&gt;

&lt;P&gt;If it is KVStore, maybe you'd prefer it to be replicated to the Indexer layer for performance increase?&lt;/P&gt;

&lt;P&gt;How frequently is that lookup updated?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 13:51:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-slow-performance/m-p/397846#M115450</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2019-02-26T13:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups slow performance</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-slow-performance/m-p/397847#M115451</link>
      <description>&lt;P&gt;It depends on how many definitions exist to create the field &lt;CODE&gt;guid&lt;/CODE&gt; and what types they are.  This is a VERY deep topic.  Start here and pay special attention to the parts regarding &lt;CODE&gt;lispy&lt;/CODE&gt;:&lt;BR /&gt;
&lt;A href="https://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf"&gt;https://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf&lt;/A&gt;&lt;BR /&gt;
Also check out this:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/2871/"&gt;https://splunkbase.splunk.com/app/2871/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If the field &lt;CODE&gt;guid&lt;/CODE&gt; is an indexed field, then you can use this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=my_index guid::my_guid 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 03 Mar 2019 05:14:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-slow-performance/m-p/397847#M115451</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-03T05:14:09Z</dc:date>
    </item>
  </channel>
</rss>

