Splunk Search

Database lookup not returning all matches

sc0tt
Builder

I have created a database lookup and have changed the maximum matches in the lookup defintion to 100, but only 1 match is being returned. I am using DB Connect 1.1.2 with an Oracle database.

Any suggestions?

0 Karma
1 Solution

ziegfried
Influencer

You need to set max_matches in the corresponding stanza in both transforms.conf and dblookup.conf. Have you restarted Splunk after making those changes?

View solution in original post

karthi4k
Explorer

Hi, I have a lookup whose maximum match is 249. I've set the "max_matches" to 300 but the maximum it returns is only 99. Is it the limit? Are there any other settings I need to modify? Any help would be appreciated.

0 Karma

ziegfried
Influencer

You need to set max_matches in the corresponding stanza in both transforms.conf and dblookup.conf. Have you restarted Splunk after making those changes?

sroback_splunk
Splunk Employee
Splunk Employee

Hi. Yes, the subject of editing dblookup.conf and transforms.conf files to create a lookup that returns more than the default number of one match is covered here:

http://docs.splunk.com/Documentation/DBX/1.1.3/DeployDBX/Setupadatabaselookuptable#Create_a_lookup_b...

sc0tt
Builder

I did not edit the config files. I only made the change in the Lookup definitions via Splunk web. Adding max_matches to dblookup.conf fixed the issue. Is it documented anywhere that you need to make changes to this file as well? Thanks!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...