- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SamHTexas
Builder
03-12-2021
09:44 AM
What Splunk server should contain the lookup tables for all servers to use?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
03-12-2021
01:26 PM
If the SH is part of a cluster then, yes, put the lookup file on one of them and the SH will replicate it to others.
If the SHs are not clustered then you'll have to create the lookup on all of them.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SamHTexas
Builder
03-12-2021
12:43 PM
Great, so do I create lookup tables only on one SH or all please?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
03-12-2021
01:26 PM
If the SH is part of a cluster then, yes, put the lookup file on one of them and the SH will replicate it to others.
If the SHs are not clustered then you'll have to create the lookup on all of them.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
03-12-2021
12:37 PM
Lookup files are stored on search heads. They're sent to indexers as part of the search bundle.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
