Splunk Search

What are lookups for INGEST_EVAL in distributed deployment?

ilya_resh
Engager

Hi,

Distributed deployment that includes SH Cluster and IDX Cluster, HEC on IDXs is used to receive the data.
I want to use ingest time lookups BUT the lookup will need to be refreshed (let's say hourly).

Now the question is how will that work?


SHs can refresh a lookup and it will be pushed as part of the search bundle to the IDXs, but I don't think IDXs will know how to use it for ingest time lookup (as this bundle is used during search time), would they?

The only option I can think of is to run the scheduled search that populates the lookup on Cluster Master but tell it to output the lookup into the `slave_apps` folder, but that will require to push a new IDX bundle every time.....

 

Any thoughts on how to do it?

Thanks.

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...