<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are there any use cases that justify the over-head of automatic lookups? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Are-there-any-use-cases-that-justify-the-over-head-of-automatic/m-p/421492#M121049</link>
    <description>&lt;P&gt;Thanks @grittonc!&lt;/P&gt;

&lt;P&gt;I've added the best-practices tag and will review this when we start work on lookups (no ETA). Thanks again!&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2019 13:10:36 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2019-06-07T13:10:36Z</dc:date>
    <item>
      <title>Are there any use cases that justify the over-head of automatic lookups?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-any-use-cases-that-justify-the-over-head-of-automatic/m-p/421490#M121047</link>
      <description>&lt;P&gt;Our team discourages all users from using  automatic lookups due to the over-head incurred in each search query. &lt;/P&gt;

&lt;P&gt;Are there any best practices around it?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2019 14:42:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-any-use-cases-that-justify-the-over-head-of-automatic/m-p/421490#M121047</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2019-04-22T14:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: Are there any use cases that justify the over-head of automatic lookups?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-any-use-cases-that-justify-the-over-head-of-automatic/m-p/421491#M121048</link>
      <description>&lt;P&gt;@SloshBurch this sounds like a job for the best practices tag.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2019 17:37:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-any-use-cases-that-justify-the-over-head-of-automatic/m-p/421491#M121048</guid>
      <dc:creator>grittonc</dc:creator>
      <dc:date>2019-04-22T17:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Are there any use cases that justify the over-head of automatic lookups?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-any-use-cases-that-justify-the-over-head-of-automatic/m-p/421492#M121049</link>
      <description>&lt;P&gt;Thanks @grittonc!&lt;/P&gt;

&lt;P&gt;I've added the best-practices tag and will review this when we start work on lookups (no ETA). Thanks again!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 13:10:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-any-use-cases-that-justify-the-over-head-of-automatic/m-p/421492#M121049</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2019-06-07T13:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Are there any use cases that justify the over-head of automatic lookups?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Are-there-any-use-cases-that-justify-the-over-head-of-automatic/m-p/421493#M121050</link>
      <description>&lt;P&gt;I would say that lookups that translate things into human, for example protocol numbers like 6 and 17 are TCP and UDP would be a good candidates.  In this specific case the data set is limited, and, instead of doing all ~150 in a lookup you could do like the top 10 or 20 and even just put those into a regular  &lt;CODE&gt;.props&lt;/CODE&gt; "case" statement instead of a lookup.  &lt;/P&gt;

&lt;P&gt;One of the other main usecases I've used is user enrichment, where you have log events with users and everytime you want to investigate something you always need to know who is this user, what department are they in, what is their SAM acct, their phone, their email, the last time their password was changed, etc.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 23:33:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Are-there-any-use-cases-that-justify-the-over-head-of-automatic/m-p/421493#M121050</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2019-07-10T23:33:19Z</dc:date>
    </item>
  </channel>
</rss>

