Splunk Search

Database lookup not returning all matches

sc0tt
Builder

I have created a database lookup and have changed the maximum matches in the lookup defintion to 100, but only 1 match is being returned. I am using DB Connect 1.1.2 with an Oracle database.

Any suggestions?

0 Karma
1 Solution

ziegfried
Influencer

You need to set max_matches in the corresponding stanza in both transforms.conf and dblookup.conf. Have you restarted Splunk after making those changes?

View solution in original post

karthi4k
Explorer

Hi, I have a lookup whose maximum match is 249. I've set the "max_matches" to 300 but the maximum it returns is only 99. Is it the limit? Are there any other settings I need to modify? Any help would be appreciated.

0 Karma

ziegfried
Influencer

You need to set max_matches in the corresponding stanza in both transforms.conf and dblookup.conf. Have you restarted Splunk after making those changes?

sroback_splunk
Splunk Employee
Splunk Employee

Hi. Yes, the subject of editing dblookup.conf and transforms.conf files to create a lookup that returns more than the default number of one match is covered here:

http://docs.splunk.com/Documentation/DBX/1.1.3/DeployDBX/Setupadatabaselookuptable#Create_a_lookup_b...

sc0tt
Builder

I did not edit the config files. I only made the change in the Lookup definitions via Splunk web. Adding max_matches to dblookup.conf fixed the issue. Is it documented anywhere that you need to make changes to this file as well? Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...