We are using Splunk ES version 5.2. The size of the indentities_expanded CSV file is over 350MB and is causing issues with the search bundle replication. Can this lookup be changed to a kvstore instead? I did try and convert it but it reverts back to a file based lookup automatically?
In 6.0 there's a new behavior that sounds like what you're looking for:
"Leverage KV store as a new interface for Assets and Identities. Allow for extensible fields in the Assets and Identities table definition, as well as enhance scalability/performance so that customers with very large, csv-based lookup files can easily administer their ES environments with fewer bundle replication related issues."