Splunk Search

Lookup limits


We have a CSV table from where we perform lookups. The CSV file has nearly 50000 rows. When I run the lookup query, results are not returned for some of the rows. I picked one value for which lookup was not happening, made its entry the first row (earlier it was the 5286th row) in the CSV and reduced the number of rows in the CSV to 3. The lookup was then successful.

Is there any limit to the number of rows that will be looked up when we run lookup command?

I checked the max_memtable_bytes value in my limits.conf and the CSV table size is way below the limit. We use Splunk version 5.0.4



Re: Lookup limits


Check for unmatched/Orphan double quotes in your CSV files. That will cause problem and lookups wont be complete.

