Hi splunkers!
I have a large lookup that is fully updated once a day.
The first time I address this lookup each day, it takes way too long time to get results.
After such initial reindexing or loading (not sure), further searches are calculated with normal speed.
Is it possible to preload/reindex it,not at a search-time, but beforehand, e.g. just after it's done updating on a schedule for all users?
Thank you!
You could schedule a search that uses the lookup shortly after the scheduled time, causing Splunk to look at the lookup and force a rebuild of the lookup's ad-hoc index.
You could schedule a search that uses the lookup shortly after the scheduled time, causing Splunk to look at the lookup and force a rebuild of the lookup's ad-hoc index.
It worked! Great, thank you Martin!