Splunk Enterprise

Best Practice for Automatic Lookups

jaburke1
Path Finder

Is there a suggested size of lookup that would be the maximum size of a lookup that should be used for an automatic lookup?

Such as if your lookup exceeds more than x rows it would best not to use with an automatic lookup?

 

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm not sure there are best practices around automatic lookups.  There are some for lookups in general, however.  Monitor lookup size (in bytes) to make sure they don't cause the knowledge bundle to become too large (2GB).  Large lookups should be blocked from the bundle or converted to KVStore.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jaburke1
Path Finder

Thanks Rich! Is it a bad practice to use a KVStore for automatic lookups since they can get very large?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I wouldn't say that at all.  One of the features of KVStore is to replace large lookup files.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...