Splunk Search

What are lookups for INGEST_EVAL in distributed deployment?

ilya_resh
Engager

Hi,

Distributed deployment that includes SH Cluster and IDX Cluster, HEC on IDXs is used to receive the data.
I want to use ingest time lookups BUT the lookup will need to be refreshed (let's say hourly).

Now the question is how will that work?


SHs can refresh a lookup and it will be pushed as part of the search bundle to the IDXs, but I don't think IDXs will know how to use it for ingest time lookup (as this bundle is used during search time), would they?

The only option I can think of is to run the scheduled search that populates the lookup on Cluster Master but tell it to output the lookup into the `slave_apps` folder, but that will require to push a new IDX bundle every time.....

 

Any thoughts on how to do it?

Thanks.

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...