Splunk Search

Efficient filtering with high number of values from a lookup table

Simon
Contributor

Hi all,

I've got 16k and growing values in a CSV. I'd like to search for events matching those values, like

tag::eventtype="authentication" [| inputlookup cmdb_former_employees | fields user | return 999999 user ]

But it seems that this is pretty much inefficient and results in a very slow search.
Is there a better way to find events matching a large set of values form a lookup?

Thanks,
Simon

Tags (3)
0 Karma

starcher
Influencer

I'd try making that an auto lookup for the relevant sourcetypes.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...