Splunk Search

Lookup csv

wj
Engager

May I know if there is any size limit of the csv file when performing a lookup?

I'm doing a lookup to a csv with around 300k records, encounter the error below.

Encountered an error while reading file 'D:\Splunk\var\run\splunk\dispatchtmp\subsearch_admin__admin__search

Thanks

Tags (2)
0 Karma

MillerTime
Splunk Employee
Splunk Employee

Upgrading Splunk to 4.3.4 should fix the issue

0 Karma

Drainy
Champion

Is that the exact error? It looks similar to a current splunk bug on 4.3.3 which occurs when you have a sub search in your search string. Csvs can contain many many more records than 300k so it could be the aforementioned bug you are hitting instead.

Update:

Subsearch failing with the error "Encountered an error while reading file '/opt/splunk/var/run/splunk/dispatchtmp/subsearch_/prereport_.csv.gz'.", the workaround is to format the fields with the command fields instead of table at the end of the sub search. (SPL-52862)

Drainy
Champion

Yeah this sounds like the bug. No subsearch included? Also it may pop up somewhere else. Bear in mind that CSV at the end of that is unrelated to the fact that you may be using a CSV in your search. I've updated my answer with the bug detail. I believe a fix is due in the next maintenance release.

0 Karma

wj
Engager

Hi Drainy,

The full error message.

Encountered an error while reading file 'D:\Splunk\var\run\splunk\dispatchtmp\subsearch_admin_admin_search_TWFsaWNpb3VzIElQIHNlYXJjaCBieSBkc3Q_1344931019.717_1344931019.1\collapse-132809093_0.csv.gz'.

I was able to perform the same search with a smaller csv file though.

Thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...