<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Acceleration - Search including lookup in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Acceleration-Search-including-lookup/m-p/159255#M44934</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I do it like this in the search string:&lt;/P&gt;

&lt;P&gt;my search | lookup file.csv user_id OUTPUT last_activity |&lt;/P&gt;

&lt;P&gt;The last_activity per user is written to the lookupfile each day at 00:00. So the last activity can change every time per user_id when the lookupfile is updated.&lt;/P&gt;

&lt;P&gt;What I need is, that the latest last_activity is used for all former events per user_id, when I run the accelerated search.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 15:56:41 GMT</pubDate>
    <dc:creator>HeinzWaescher</dc:creator>
    <dc:date>2020-09-28T15:56:41Z</dc:date>
    <item>
      <title>Acceleration - Search including lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Acceleration-Search-including-lookup/m-p/159253#M44932</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I would like to use Report Acceleration. My search is using a lookupfile and this lookupfile is updated once a day. Will the acceleration write the summary before using the lookup? So that the search will always use the latest version/information of my lookupfile?&lt;/P&gt;

&lt;P&gt;BG&lt;/P&gt;

&lt;P&gt;Heinz&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 10:34:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Acceleration-Search-including-lookup/m-p/159253#M44932</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2014-02-20T10:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: Acceleration - Search including lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Acceleration-Search-including-lookup/m-p/159254#M44933</link>
      <description>&lt;P&gt;Hello Heinz,&lt;/P&gt;

&lt;P&gt;If you create an Automatic lookup with your lookupfile the updated information will be accelerated when you modify your file. &lt;/P&gt;

&lt;P&gt;Best regards,&lt;/P&gt;

&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 10:40:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Acceleration-Search-including-lookup/m-p/159254#M44933</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2014-02-20T10:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: Acceleration - Search including lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Acceleration-Search-including-lookup/m-p/159255#M44934</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I do it like this in the search string:&lt;/P&gt;

&lt;P&gt;my search | lookup file.csv user_id OUTPUT last_activity |&lt;/P&gt;

&lt;P&gt;The last_activity per user is written to the lookupfile each day at 00:00. So the last activity can change every time per user_id when the lookupfile is updated.&lt;/P&gt;

&lt;P&gt;What I need is, that the latest last_activity is used for all former events per user_id, when I run the accelerated search.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:56:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Acceleration-Search-including-lookup/m-p/159255#M44934</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2020-09-28T15:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Acceleration - Search including lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Acceleration-Search-including-lookup/m-p/159256#M44935</link>
      <description>&lt;P&gt;Hello again,&lt;/P&gt;

&lt;P&gt;So your CSV file contains the last activity and the other info is from your search ?&lt;/P&gt;

&lt;P&gt;Try using Automatic lookups instead of a lookup file that way you won't need to use the 'lookup' command but as far as Acceleration goes I think that once you accelerate a certain search, the results of the acceleration dont get modified over time unless you explicitly program schedule the search to run everyday after the lookupfile is re-written.&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2014 14:49:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Acceleration-Search-including-lookup/m-p/159256#M44935</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2014-02-21T14:49:34Z</dc:date>
    </item>
  </channel>
</rss>

