Splunk Search

Lookup File data retention Question

newbie2tech
Communicator

Hi Team,

I have requirement to show last 90 days worth of app login stats broken by day.

I have a lookup table/defnition created and i have saved search that writes the summary data every morning 5 am for the previous day onto the lookup.

Question i got, is there any time limitation until which lookup will retain this data before which it starts truncating or deleting data? I expect the data would remain intact however i wanted to check with wider audience to see how your experiece has been.

I understand better way would be to either create summary index or kv store, i am not going that route as it would need 2 weeks to get it out to production in my space and i need something quick.

Please share your thoughts.

Mine is clustered environment (both SH & indexers) , version is 6.6+

Thanks!

0 Karma

pradeepkumarg
Influencer

There is no retention for lookups. The lookup will stay until some one deletes it or overwrites it.

0 Karma

kvswathi
Path Finder

Hey , you can try "Search-Driven Lookup" , there you can set retention for a lookup.

https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Createsearchdrivenlookups

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...