<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookups load 500 times in one search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491082#M137117</link>
    <description>&lt;P&gt;Hi @misteraufziehvogel,&lt;/P&gt;

&lt;P&gt;Do you mean that your &lt;CODE&gt;sourcetypes&lt;/CODE&gt; are using &lt;CODE&gt;automatic lookups&lt;/CODE&gt; and when you run &lt;CODE&gt;index=*&lt;/CODE&gt; all lookups are running at the same time ?&lt;/P&gt;

&lt;P&gt;If you're trying to avoid that make sure you set your search type to fast mode instead of verbose.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
    <pubDate>Tue, 19 Nov 2019 08:48:34 GMT</pubDate>
    <dc:creator>DavidHourani</dc:creator>
    <dc:date>2019-11-19T08:48:34Z</dc:date>
    <item>
      <title>Lookups load 500 times in one search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491081#M137116</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;the environment uses 170 lookups and during one single search, they get loaded exactly 500 times each wich sums up to thousands of times in total and a search job total of 800mb as long as we type index=*. I know I know, you shouldn't do that, but our customer did and this obviously is a bug (selfmade?). Btw: All lookups are set to global. &lt;/P&gt;

&lt;P&gt;What happens here? How can we change it? &lt;BR /&gt;
Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 08:36:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491081#M137116</guid>
      <dc:creator>misteraufziehvo</dc:creator>
      <dc:date>2019-11-19T08:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups load 500 times in one search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491082#M137117</link>
      <description>&lt;P&gt;Hi @misteraufziehvogel,&lt;/P&gt;

&lt;P&gt;Do you mean that your &lt;CODE&gt;sourcetypes&lt;/CODE&gt; are using &lt;CODE&gt;automatic lookups&lt;/CODE&gt; and when you run &lt;CODE&gt;index=*&lt;/CODE&gt; all lookups are running at the same time ?&lt;/P&gt;

&lt;P&gt;If you're trying to avoid that make sure you set your search type to fast mode instead of verbose.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 08:48:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491082#M137117</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-11-19T08:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups load 500 times in one search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491083#M137118</link>
      <description>&lt;P&gt;Hi @DavidHourani,&lt;/P&gt;

&lt;P&gt;changing the search type doesn't change anything unfortunately. But I got closer to the answer: We do have 506 Indizes and all Lookups get loaded for every single Index..... we will be starting a campaign for the employees: Specify the Index &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 09:25:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491083#M137118</guid>
      <dc:creator>misteraufziehvo</dc:creator>
      <dc:date>2019-11-19T09:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups load 500 times in one search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491084#M137119</link>
      <description>&lt;P&gt;yes, also make also make sure you select the appropriate index filter per role to reduce the load and try to avoid automatic lookups unless they are vital for your sourcetype.&lt;/P&gt;

&lt;P&gt;Have a look at the answer below could help you forge some searches that won't call the automated lookups :&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/113653/ignore-automatic-lookup-just-for-a-search.html"&gt;https://answers.splunk.com/answers/113653/ignore-automatic-lookup-just-for-a-search.html&lt;/A&gt;&lt;BR /&gt;
The again when you automate something it means you need to be applied every single time... ends up backfiring when you have so many lookups &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 09:33:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491084#M137119</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-11-19T09:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Lookups load 500 times in one search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491085#M137120</link>
      <description>&lt;P&gt;I think you may have one more issue to look-at. Look-ups (even if they are global and automatic) should be normally restricted to one sourcetype (can't see why we would enable across sourcetypes). So, you may want to look at that as well. Also, for users, you can default 'indexes' to search in the roles definition. So, if anyone uses index=* , it will restrict them to default ones, as opposed to search across all indexes, till the education/campaign is successful.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 09:52:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookups-load-500-times-in-one-search/m-p/491085#M137120</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-11-19T09:52:21Z</dc:date>
    </item>
  </channel>
</rss>

