I noticed in search.log that there are "INFO LookupOperator - Loading lookup table=..." log events that don't apply to the sourcetypes specified in the search. Later there is another event that says "INFO LookupOperator - Disabling automatic lookup of table=..."
Why is Splunk loading lookup tables that aren't used by any of the source types specified in the search?
↧