SPLK-1001 Using Fields and Lookups • Set 3
SPLK-1001 Using Fields and Lookups Practice Test 3 — 15 questions with explanations. Free, no signup.
You are a Splunk admin for a large enterprise with multiple distributed Splunk components. The security team frequently runs searches that use a large CSV lookup file (500MB) containing threat intelligence indicators. They report that searches are slow and sometimes time out. The lookup file is updated hourly via an automated script. The team currently uses the 'lookup' command in every search. You need to improve performance without sacrificing data freshness. Your environment has a search head cluster and indexer cluster. The lookup file is stored on a shared filesystem accessible to all search heads. Which single approach will best improve search performance while maintaining hourly updates?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.