Hi all, we have a non-clustered distributed Splunk. It has a number of big lookup files that are updated regularly. As such, the config bundle became too big and I have to set [replicationBlacklist] in distsearch.conf , 1 entry per lookup file exclusion. We add local=t for lookup queries and things are fine.
However, we notice another unrelated lookup table starts having does not exist error from time to time, not all the time. Restarting the Splunk head helps but that's not ideal. It is used in an inputlookup query so there is no local=t option.
What is the recommended action here? Has anyone seen this before? Thanks,
... View more