Deployment Architecture

Automatic replication of lookup to indexer

derchrischkya
Engager

Dear Splunkers,

actual i am facing an issue, we have an Lookup on the SHC with some location infromation e.g location.csv

 

____

location

DE

EN

 

Scope is to ingest data only on indexers, when the location in events showing up on lookups too. The solution works with ingest_eval and lookup filtering.

 

The question right know is do we have the possibility to manage this lookup on SH level and provide some roles the permission to add/remove locations on their demand from this index.

e.g. I'll update the lookup on the SH and this will be replicated to lookup on Index Cluster too..how can i achieve this one?

Kind Regards

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @derchrischkya,

lookups are only on Search Heads, infact usually KV-Store is disabled on Indexers.

The only ways to replicate lookups are:

  • have a Search Head Cluster, where Lookups are automatically replicated between Search Heads,
  • don't use lookups but Summary Indexes, that are saved on Indexers.

You can use a summary index  as a lookup creating a scheduled search that saves in the summary index the same content of the lookup (e.g. every day).

Ciao.

Giuseppe

Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...