Which is more efficient, a scripted lookup or a command?
I've written a piece of code as both, and the command is certainly easier to write, and I would never want to wire this particular lookup to run automatically, so unless the lookup is more efficient, I see no reason to not write the code as a command.
Thoughts?
splunk-base has a good pro and con list on this: