Splunk Search

Lookup limits

keerthana_k
Communicator

We have a CSV table from where we perform lookups. The CSV file has nearly 50000 rows. When I run the lookup query, results are not returned for some of the rows. I picked one value for which lookup was not happening, made its entry the first row (earlier it was the 5286th row) in the CSV and reduced the number of rows in the CSV to 3. The lookup was then successful.

Is there any limit to the number of rows that will be looked up when we run lookup command?

I checked the max_memtable_bytes value in my limits.conf and the CSV table size is way below the limit. We use Splunk version 5.0.4

Thanks,

Keerthana

Tags (1)
1 Solution

strive
Influencer

Check for unmatched/Orphan double quotes in your CSV files. That will cause problem and lookups wont be complete.

View solution in original post

strive
Influencer

Check for unmatched/Orphan double quotes in your CSV files. That will cause problem and lookups wont be complete.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...