Splunk Search

What are lookups for INGEST_EVAL in distributed deployment?

ilya_resh
Engager

Hi,

Distributed deployment that includes SH Cluster and IDX Cluster, HEC on IDXs is used to receive the data.
I want to use ingest time lookups BUT the lookup will need to be refreshed (let's say hourly).

Now the question is how will that work?


SHs can refresh a lookup and it will be pushed as part of the search bundle to the IDXs, but I don't think IDXs will know how to use it for ingest time lookup (as this bundle is used during search time), would they?

The only option I can think of is to run the scheduled search that populates the lookup on Cluster Master but tell it to output the lookup into the `slave_apps` folder, but that will require to push a new IDX bundle every time.....

 

Any thoughts on how to do it?

Thanks.

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...