Splunk Search

How can I specify specific lines within my lookup file to search against?

the_wolverine
Champion

I have a large resultset, lookupb.csv which consists of about 4 million lines, that I'm searching against that I need to break up in order to bypass the 10k result limit in subsearch.

Example:

| inputlookup lookupa.csv | search NOT [ |inputlookup lookupb.csv | head 10000 | fields fieldname ]

Obviously, I have a way to get 10000 first lines, and maybe 10000 last lines, but what about in-between?

0 Karma
1 Solution

somesoni2
Revered Legend

One option could be to have serial no in the lookup file itself or add serial no in subsearch and search based on it.

|inputlookup lookupb.csv | eval sno=1 | accum sno | where sno >= yourlowerlimit AND sno <= yourupperlimit

Also, consider option to increase the limit value in limits.conf so that there are less no of breakups.

View solution in original post

the_wolverine
Champion

That worked! Make it an answer so I can accept it.

0 Karma

somesoni2
Revered Legend

One option could be to have serial no in the lookup file itself or add serial no in subsearch and search based on it.

|inputlookup lookupb.csv | eval sno=1 | accum sno | where sno >= yourlowerlimit AND sno <= yourupperlimit

Also, consider option to increase the limit value in limits.conf so that there are less no of breakups.

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...