I have a set of log data that contains userids, and want to do a lookup to resolve the userid to an email address. I have an external look that can programmatically resolve each user's id, but am wondering (assuming I have a 4 node cluster) if splunk will execute 4 instances of the lookup script in parallel or if it only launches one (or if it's configurable?)
Normally, Splunk sends the lookup file from the Search Head in the bundle replication process to the Indexers and the lookups are done there. However, you can force the lookups to be done on the search head with the local=true:
Description: If local=true, forces the lookup to run on the search head and not on any remote peers.
Obviously, this can very drastically impact performance because some of the normally-reduced job may now have to be done on the Search Head.