nerdexam
Splunk

SPLK-3003 · Question #50

A customer with a large distributed environment has blacklisted a large lookup from the search bundle to decrease the bundle size using distsearch.conf. After this change, when running searches…

The correct answer is A. The search needs to be modified to ensure the lookup command specifies parameter local=true. https://community.splunk.com/t5/Splunk-Search/Large-lookup-caused-the-bundle-replication-to- fail-What-are-my/m-p/194594

Search Performance and Optimization

Question

A customer with a large distributed environment has blacklisted a large lookup from the search bundle to decrease the bundle size using distsearch.conf. After this change, when running searches utilizing the lookup that was blacklisted they see error messages in the Splunk Search UI stating the lookup file does not exist. What can the customer do to resolve the issue?

Options

  • AThe search needs to be modified to ensure the lookup command specifies parameter local=true.
  • BThe blacklisted lookup definition stanza needs to be modified to specify setting
  • CThe search needs to be modified to ensure the lookup command specified parameter
  • DThe lookup cannot be blacklisted; the change must be reverted.

How the community answered

(20 responses)
  • A
    65% (13)
  • B
    5% (1)
  • C
    10% (2)
  • D
    20% (4)

Explanation

https://community.splunk.com/t5/Splunk-Search/Large-lookup-caused-the-bundle-replication-to- fail-What-are-my/m-p/194594

Topics

#distsearch.conf#search bundle#lookup blacklist#local lookup

Community Discussion

No community discussion yet for this question.

Full SPLK-3003 Practice