I have scheduled search jobs that run nightly. The first search adds fields A and B for the day to the lookup. The second search imports the CSV adds field C. When the second job executes it gets stuck "parsing job" for 30 minutes before finally progressing into the execution phase.
My lookup file is only ~5MB, why so slow to parse the job?
|inputlookup mylookup.csv append=true
| join type=left host, _time
[search index=my_idx FieldC
| bucket _time span=d
| dedup host, _time]
| where _time>=relative_time(now(),"-30d")
| table host, FieldA, FieldB, FieldC
| outputlookup mylookup.csv
... View more