Splunk Search

Is it possible to reindex or preload a large lookup automatically for a user?

iKate
Builder

Hi splunkers!

I have a large lookup that is fully updated once a day.
The first time I address this lookup each day, it takes way too long time to get results.
After such initial reindexing or loading (not sure), further searches are calculated with normal speed.

Is it possible to preload/reindex it,not at a search-time, but beforehand, e.g. just after it's done updating on a schedule for all users?

Thank you!

Tags (1)
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You could schedule a search that uses the lookup shortly after the scheduled time, causing Splunk to look at the lookup and force a rebuild of the lookup's ad-hoc index.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You could schedule a search that uses the lookup shortly after the scheduled time, causing Splunk to look at the lookup and force a rebuild of the lookup's ad-hoc index.

iKate
Builder

It worked! Great, thank you Martin!

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...