Splunk Enterprise

Best Practice for Automatic Lookups

jaburke1
Path Finder

Is there a suggested size of lookup that would be the maximum size of a lookup that should be used for an automatic lookup?

Such as if your lookup exceeds more than x rows it would best not to use with an automatic lookup?

 

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm not sure there are best practices around automatic lookups.  There are some for lookups in general, however.  Monitor lookup size (in bytes) to make sure they don't cause the knowledge bundle to become too large (2GB).  Large lookups should be blocked from the bundle or converted to KVStore.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jaburke1
Path Finder

Thanks Rich! Is it a bad practice to use a KVStore for automatic lookups since they can get very large?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I wouldn't say that at all.  One of the features of KVStore is to replace large lookup files.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...