Also please guide me on how to optimize my Lookups for more efficiency. When does one use Lookups vs KVstores? Thank u very much
if you're using the outputlookup command you have the limit of 10,000 results
In addition I have in mind the limit of 50,000 rows, but I don't remember where I saw this.
Anyway, in the choose between csv and KV Store you should have in mind two thing:
if you have a static tavble you can use csv, if you have a frequently modified table, it's better to use KV Store.
About number of rows, until some thousands of rows (1000, 2000) I continue to use csv, then I'd pass to KV store.
In addition, if you have to update some fields of some rows (as a db), it's easier to use KV Store because the table unique key is managed by Splunk.
View solution in original post