Splunk Search

Will Splunk searches using lookup get affected if there is knowledge bundle issue?

Sucheta_new
Loves-to-Learn

So I have been working on migrating usecases from one splunk ES to splunk cloud for a client. They had around 760+ correlation searches created for similar usecases and field extraction. So I created a lookup and used lookup definition to create the correlation search.

They are pointing out that this might affect the notable creation when there is a knowledge bundle fail. Also they highlighted it will lead to skipped searches.

I have built similar cases for other environments with more huge lookup and search over huge data. My present lookup have 764 entries and the correlation search runs for every 15min cron looking back on the 1hour data.

 

so I would like the help of the experts, to answer 

 

1. if consolidating 760 separate searches are efficient or 1search with the lookup is efficient and how

2. In case of knowledge bundle fail will it be affected and miss alerting?

3. Will it cause skipped searches if the schedule goes over?

p.s. - However my search should re trigger and anyhow is checking over last 1hour data every 15min

please help on this matter

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...