Splunk Search

Lookup limits

keerthana_k
Communicator

We have a CSV table from where we perform lookups. The CSV file has nearly 50000 rows. When I run the lookup query, results are not returned for some of the rows. I picked one value for which lookup was not happening, made its entry the first row (earlier it was the 5286th row) in the CSV and reduced the number of rows in the CSV to 3. The lookup was then successful.

Is there any limit to the number of rows that will be looked up when we run lookup command?

I checked the max_memtable_bytes value in my limits.conf and the CSV table size is way below the limit. We use Splunk version 5.0.4

Thanks,

Keerthana

Tags (1)
1 Solution

strive
Influencer

Check for unmatched/Orphan double quotes in your CSV files. That will cause problem and lookups wont be complete.

View solution in original post

strive
Influencer

Check for unmatched/Orphan double quotes in your CSV files. That will cause problem and lookups wont be complete.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...