Splunk Search

Are there any search limits for inputlookup and then lookup another kv_store?

jbanAtSplunk
Communicator

hi,

I have two KV_Store lookups as they are huge:
* one is more than 250k rows
* second and 65k rows. 

In "250k" row lookup is only IP while in second one are IP CIDR+LIST

So,  I do search like

 

 

| inputlookup list_250k
| rename ip_cidr as ip
| eval convert_ip=tostring(ip)
| lookup list_65k ip_cidr AS convert_ip OUTPUT ip_cidr, list
| where isNotNull(ip_cidr)
| rename ip_cidr as found_in

 

 

 I am getting results. I am curious are there any limits?
if for example search is limited, would I see some error  (as there is no progress bar that it's working something)?

Labels (1)
0 Karma

dhruv
Explorer

AFAIK, There is no limitation. It might take some time if there are a lot of records in kvstore but no limitations.
https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/SearchReference/Lookup

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...