Monitoring Splunk

Performance implication of automatic lookups

andrewbeak
Path Finder

We need to group our hosts by customer and environment. I've created a lookup for this and it's working without any problems.

What are the performance implications of including this as an automatic lookup?

1 Solution

mayurr98
Super Champion

Adding the lookup automatically isn't a great performance impact for reporting searches, ie ones that have a stats, chart, table, ... at the end. Splunk will only add the fields from the lookup if the reporting commands require the fields.
The performance impact comes in only if you filter by fields added by the lookup.

View solution in original post

mayurr98
Super Champion

Adding the lookup automatically isn't a great performance impact for reporting searches, ie ones that have a stats, chart, table, ... at the end. Splunk will only add the fields from the lookup if the reporting commands require the fields.
The performance impact comes in only if you filter by fields added by the lookup.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...