Deployment Architecture

Automatic replication of lookup to indexer

derchrischkya
Engager

Dear Splunkers,

actual i am facing an issue, we have an Lookup on the SHC with some location infromation e.g location.csv

 

____

location

DE

EN

 

Scope is to ingest data only on indexers, when the location in events showing up on lookups too. The solution works with ingest_eval and lookup filtering.

 

The question right know is do we have the possibility to manage this lookup on SH level and provide some roles the permission to add/remove locations on their demand from this index.

e.g. I'll update the lookup on the SH and this will be replicated to lookup on Index Cluster too..how can i achieve this one?

Kind Regards

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @derchrischkya,

lookups are only on Search Heads, infact usually KV-Store is disabled on Indexers.

The only ways to replicate lookups are:

  • have a Search Head Cluster, where Lookups are automatically replicated between Search Heads,
  • don't use lookups but Summary Indexes, that are saved on Indexers.

You can use a summary index  as a lookup creating a scheduled search that saves in the summary index the same content of the lookup (e.g. every day).

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...