Deployment Architecture

which technology is being used for csv lookup replication (SH/indexer replication)

pargupta1234
New Member

I want to understand which technology is being used while CSV lookup bundle replication.
Is this whole CSV gets replicated or only changes in CSV get replicated?
I checked replication logs and found that not complete CSV gets replicated so why CSV lookup replication causes SH replication issue if the size of CSV exceeds 2 GB?
What is the problem with CSV lookup that it is not good for large lookup and everyone advice to move to KV store or DB connect?

Labels (2)
0 Karma

codebuilder
Influencer

The default limit for knowledge bundle replication is 2GB, it's not specific to lookups.
KV Store is generally recommended for lookups greater than 100MB because it is DB based (Mongo) and therefore much faster and more efficient.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...