Splunk Search

When do I move Lookup files to a KVstore? How big is the limit of the Lookup File before moving it to a KVstore? Please.

SamHTexas
Builder

Also please guide me on how to optimize my Lookups for more efficiency. When does one use Lookups vs KVstores? Thank u very much

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

if you're using the outputlookup command you have the limit of 10,000 results

In addition I have in mind the limit of 50,000 rows, but I don't remember where I saw this.

Anyway, in the choose between csv and KV Store you should have in mind two thing:

  • number of rows,
  • staticity.

if you have a static  tavble you can use csv, if you have a frequently modified table, it's better to use KV Store.

About number of rows, until some thousands of rows (1000, 2000) I continue to use csv, then I'd pass to KV store.

In addition, if you have to update some fields of some rows (as a db), it's easier to use KV Store because the table unique key is managed by Splunk.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

if you're using the outputlookup command you have the limit of 10,000 results

In addition I have in mind the limit of 50,000 rows, but I don't remember where I saw this.

Anyway, in the choose between csv and KV Store you should have in mind two thing:

  • number of rows,
  • staticity.

if you have a static  tavble you can use csv, if you have a frequently modified table, it's better to use KV Store.

About number of rows, until some thousands of rows (1000, 2000) I continue to use csv, then I'd pass to KV store.

In addition, if you have to update some fields of some rows (as a db), it's easier to use KV Store because the table unique key is managed by Splunk.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk New Course Releases for a Changing World

Every day, the world feels like it’s moving faster with new technological breakthroughs, AI innovation, and ...