<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I locate KVstore &amp;amp; scripted based look ups? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-locate-KVstore-amp-scripted-based-look-ups/m-p/545246#M90917</link>
    <description>&lt;P&gt;Grazie, I see my .csv files under the definitions &amp;amp; located some scripts also there via a SH GUI. How about KSstores? Do they have to be edited via CLI?&lt;/P&gt;</description>
    <pubDate>Thu, 25 Mar 2021 01:56:17 GMT</pubDate>
    <dc:creator>SamHTexas</dc:creator>
    <dc:date>2021-03-25T01:56:17Z</dc:date>
    <item>
      <title>How do I locate KVstore &amp; scripted based look ups?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-locate-KVstore-amp-scripted-based-look-ups/m-p/544699#M90864</link>
      <description>&lt;P&gt;Under lookups I see a few .csv based &amp;amp; few look up definitions. So where are the KVstore based or scripted based lookups located or are they created manually?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Mar 2021 20:27:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-locate-KVstore-amp-scripted-based-look-ups/m-p/544699#M90864</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-03-21T20:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: How do I locate KVstore &amp; scripted based look ups?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-locate-KVstore-amp-scripted-based-look-ups/m-p/544736#M90868</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228649" target="_blank" rel="noopener"&gt;@SamHTexas&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;all the lookups (file, kv-store, script, etc...) are located on the Search Heads in:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the lookups folder of each app,&lt;/LI&gt;&lt;LI&gt;the $SPLUNK_HOME/etc/system/default folder,&lt;/LI&gt;&lt;LI&gt;the $SPLUNK_HOME/etc/system/local folder,&lt;/LI&gt;&lt;LI&gt;in the user folders ($SPLUNK_HOME/etc/user/&amp;lt;user_name&amp;gt;/&amp;lt;app&amp;gt;).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;if you see few lookups, use a different filter because by default lookups are filtered by app in the dashboard.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 07:10:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-locate-KVstore-amp-scripted-based-look-ups/m-p/544736#M90868</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-22T07:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do I locate KVstore &amp; scripted based look ups?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-locate-KVstore-amp-scripted-based-look-ups/m-p/545246#M90917</link>
      <description>&lt;P&gt;Grazie, I see my .csv files under the definitions &amp;amp; located some scripts also there via a SH GUI. How about KSstores? Do they have to be edited via CLI?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 01:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-locate-KVstore-amp-scripted-based-look-ups/m-p/545246#M90917</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-03-25T01:56:17Z</dc:date>
    </item>
  </channel>
</rss>

