I don’t think it’s A, pretty sure E is right here. The supposed 10MB limit on lookup size isn’t fixed in Splunk, it can be changed in limits.conf or depends on system resources. People get tripped up because older docs mention smaller limits, but as of now there’s no hard cap like that. Agree?
I don’t think B is the trap here, it’s E. There isn’t a strict 10MB max on lookup size, that’s just not a fixed Splunk limit. The real cap depends on config (like in limits.conf) and can be much bigger, especially with KV Store or CSV lookups. If anyone thinks there’s another wrong option let me know, but pretty sure it’s E this time.
E There’s no strict 10MB max size for lookups, that limit can be adjusted in Splunk settings.
Just to confirm, does the question specify cloud vs. on-prem? Some limits differ depending on deployment type.