Splunk Enterprise

Best Practice for Automatic Lookups

jaburke1
Path Finder

Is there a suggested size of lookup that would be the maximum size of a lookup that should be used for an automatic lookup?

Such as if your lookup exceeds more than x rows it would best not to use with an automatic lookup?

 

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm not sure there are best practices around automatic lookups.  There are some for lookups in general, however.  Monitor lookup size (in bytes) to make sure they don't cause the knowledge bundle to become too large (2GB).  Large lookups should be blocked from the bundle or converted to KVStore.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jaburke1
Path Finder

Thanks Rich! Is it a bad practice to use a KVStore for automatic lookups since they can get very large?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I wouldn't say that at all.  One of the features of KVStore is to replace large lookup files.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...