Deployment Architecture

Automatic replication of lookup to indexer

derchrischkya
Engager

Dear Splunkers,

actual i am facing an issue, we have an Lookup on the SHC with some location infromation e.g location.csv

 

____

location

DE

EN

 

Scope is to ingest data only on indexers, when the location in events showing up on lookups too. The solution works with ingest_eval and lookup filtering.

 

The question right know is do we have the possibility to manage this lookup on SH level and provide some roles the permission to add/remove locations on their demand from this index.

e.g. I'll update the lookup on the SH and this will be replicated to lookup on Index Cluster too..how can i achieve this one?

Kind Regards

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @derchrischkya,

lookups are only on Search Heads, infact usually KV-Store is disabled on Indexers.

The only ways to replicate lookups are:

  • have a Search Head Cluster, where Lookups are automatically replicated between Search Heads,
  • don't use lookups but Summary Indexes, that are saved on Indexers.

You can use a summary index  as a lookup creating a scheduled search that saves in the summary index the same content of the lookup (e.g. every day).

Ciao.

Giuseppe

Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...