Thanks for the suggestion @richgalloway But I want to make sure that my application runs on the 8.0.x Splunk version as well. I've come across to know some of the approaches which may help me to run my |inputlookup <lookup_name> command in the background(through savedsearch) and I can just refer to the output of last run commands to display the lookup data on the dashboard. So when the user visits the dashboard, even the data in lookup is 15million still, it would be fairly fast. To make this happen there are again several approaches like accelerated savedsearch, savedsearch reference, data model, summary indexing, etc. Which would be the better approach if I want to run my |inputlookup <lookup_name> command in the background and once it finished and I get the stats out from the search to display on the dashboard. So I don't need to worry about how much time is taken by lookup command to execute to populate all the dashboards. Thanks in Advance!!
... View more