Monitoring Splunk
Highlighted

Performance implication of automatic lookups

Path Finder

We need to group our hosts by customer and environment. I've created a lookup for this and it's working without any problems.

What are the performance implications of including this as an automatic lookup?

Highlighted

Re: Performance implication of automatic lookups

SplunkTrust
SplunkTrust

Adding the lookup automatically isn't a great performance impact for reporting searches, ie ones that have a stats, chart, table, ... at the end. Splunk will only add the fields from the lookup if the reporting commands require the fields.
The performance impact comes in only if you filter by fields added by the lookup.

View solution in original post