<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is the automatic lookup table used by the indexer? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402330#M173722</link>
    <description>&lt;P&gt;Thanks for the Cribl info, @skoelpin.  I'll check it out.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jan 2019 13:48:42 GMT</pubDate>
    <dc:creator>rxdeleon</dc:creator>
    <dc:date>2019-01-17T13:48:42Z</dc:date>
    <item>
      <title>Is the automatic lookup table used by the indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402323#M173715</link>
      <description>&lt;P&gt;When an automatic lookup table is defined, is that used by the indexer to add the new fields or is it the search head that does that?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 17:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402323#M173715</guid>
      <dc:creator>rxdeleon</dc:creator>
      <dc:date>2019-01-10T17:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is the automatic lookup table used by the indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402324#M173716</link>
      <description>&lt;P&gt;It's the search head. The data is already indexed on the indexer so it would be a search time function&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 17:30:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402324#M173716</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-10T17:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Is the automatic lookup table used by the indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402325#M173717</link>
      <description>&lt;P&gt;Thanks, skoelpin, for the quick reply.  If that's the case, does that mean that the raw data found by the indexer would all be shipped to the search head?   And that's where the lookup table would be applied?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 17:51:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402325#M173717</guid>
      <dc:creator>rxdeleon</dc:creator>
      <dc:date>2019-01-10T17:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is the automatic lookup table used by the indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402326#M173718</link>
      <description>&lt;P&gt;Partially correct. The SH will search the data on the indexer, the indexer will not ship its data to the SH&lt;/P&gt;

&lt;P&gt;Data lives on the indexer and when a scheduled/ad-hoc search kicks off on the SH, the SH will search the data on the indexers and the automatic lookup logic will be applied at search time. A good way to think about this is, say you create an automatic lookup and want to change it after a day. You can easily change it because it's done on the fly at search time without baking any rules onto the indexers &lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 17:57:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402326#M173718</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-10T17:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is the automatic lookup table used by the indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402327#M173719</link>
      <description>&lt;P&gt;@rxdeleon please accept the answer if I answered your question &lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 18:01:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402327#M173719</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-14T18:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Is the automatic lookup table used by the indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402328#M173720</link>
      <description>&lt;P&gt;@skoelpin, I understand that the automatic lookup logic will be applied at search time.  But which component does that?  Is it the search head or the indexer?  If it's the search head, then that means the search results, no matter how big, would be sent to the search head where the automatic lookup logic would be applied.&lt;/P&gt;

&lt;P&gt;I would wish that it's the indexer that does it so that extracted fields could be used to filter out irrelevant events to minimize data being sent back to the search head (for performance reasons).&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 22:06:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402328#M173720</guid>
      <dc:creator>rxdeleon</dc:creator>
      <dc:date>2019-01-16T22:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Is the automatic lookup table used by the indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402329#M173721</link>
      <description>&lt;P&gt;It's the search head. Lookups have always been a bottleneck which is why I always tell customers that you should use a &lt;CODE&gt;stats&lt;/CODE&gt; before the &lt;CODE&gt;lookup&lt;/CODE&gt;. &lt;/P&gt;

&lt;P&gt;For index time lookups, you should check out Cribl. It integrates directly with Splunk! I had a long conversation with their CEO @clintsharp at CONF and was pretty impressed with the features it has. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://blog.cribl.io/2018/09/17/enriching-data-in-motion-with-ingest-time-lookups/"&gt;https://blog.cribl.io/2018/09/17/enriching-data-in-motion-with-ingest-time-lookups/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 23:23:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402329#M173721</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-16T23:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Is the automatic lookup table used by the indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402330#M173722</link>
      <description>&lt;P&gt;Thanks for the Cribl info, @skoelpin.  I'll check it out.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 13:48:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-the-automatic-lookup-table-used-by-the-indexer/m-p/402330#M173722</guid>
      <dc:creator>rxdeleon</dc:creator>
      <dc:date>2019-01-17T13:48:42Z</dc:date>
    </item>
  </channel>
</rss>

