I had some questions about the limits of a lookup file that I wasn't able to find when referencing documentation (below) or anywhere else in Splunk Cloud.
https://docs.splunk.com/Documentation/SplunkCloud/latest/Knowledge/DefineaKVStorelookupinSplunkWeb
Business Use Case Example:
We are ingesting logs and putting them into an index/sourcetype. We've created a search to append the sourcetype with a lookup file by an ID. This search will get updated everyday by the hour and output a new lookup. The amount of new data that gets added into the sourcetype varies in the 10s up to the 100s daily. If we keep doing it this way, the data size for the lookup on the browser will increase exponentially so I'm worried if there is a limit. Also open to recommendations on a better way of doing this.
Hello,
On our cloud stack, splunk support defined a limit of 50 MB for the lookup files.
I guess this might be variable.
Thanks
Splunk does not store lookup files on a browser.
Data in a lookup file stays there until you change it or remove the lookup file.
Any limits between join and lookup are within the join command, not the lookup.
As far as I know, there is no limit on the number of results outputlookup can process.