Hello Splunkers!
We have a situation here and need your help and experience. We are looking for best practice to work with Large CSV files (1Million Rows at least) to produce fast searches and fast dashboards.
The case is also special as these CSV files is updated daily on the below manner:
So, we need to update Splunk daily on the change of the files.
The only was I can see is to remove the index data and re-index the CSV files everyday!
I don't know actually how to do that if we need to automate the whole process or if there is a best practice better than this approach.
Appreciate your help.😊
Thanks @venkatasri for your collaboration to help. Will try to configure it and let you know how it worked 😄
Hi @Muwafi
Following links would be the starting point to read about them,
About lookups - Splunk Documentation, Define a KV Store lookup in Splunk Web - Splunk Documentation
--------------------------------------------------------
An upvote would be appreciated if it helps!