<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create a KV store that pulls events from an indexer? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-KV-store-that-pulls-events-from-an-indexer/m-p/228376#M67511</link>
    <description>&lt;P&gt;Links with details below but kvstores can be appended just like lookup tables.  So you just need to create a search like something below&lt;/P&gt;

&lt;P&gt;your search | table event,longline,domain,ip | outputlookup yourkvstorename append=true&lt;/P&gt;

&lt;P&gt;Really awesome write up on kvstores here.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZK"&gt;http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZK&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Similar question here&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/227766/is-there-an-easy-way-to-update-a-record-in-kv-stor.html"&gt;https://answers.splunk.com/answers/227766/is-there-an-easy-way-to-update-a-record-in-kv-stor.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And a link to how you can append a kvstore.&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Outputlookup"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Outputlookup&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Oct 2016 20:37:28 GMT</pubDate>
    <dc:creator>dperre_splunk</dc:creator>
    <dc:date>2016-10-03T20:37:28Z</dc:date>
    <item>
      <title>How to create a KV store that pulls events from an indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-KV-store-that-pulls-events-from-an-indexer/m-p/228375#M67510</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am trying to create a KV Store that pulls events from an indexer. It should display the Event, Log Line, Domain, and IP. Additionally, it should have a comment box and name of the person who is adding the comment pulled from the user account making the change. The comment box should also have an audit trail since numerous users are able to input a comment for an event. &lt;/P&gt;

&lt;P&gt;Can someone help me with this? How should i approach it? Any documentation that will allow me to do this?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 17:52:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-KV-store-that-pulls-events-from-an-indexer/m-p/228375#M67510</guid>
      <dc:creator>naqviah</dc:creator>
      <dc:date>2016-10-03T17:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a KV store that pulls events from an indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-KV-store-that-pulls-events-from-an-indexer/m-p/228376#M67511</link>
      <description>&lt;P&gt;Links with details below but kvstores can be appended just like lookup tables.  So you just need to create a search like something below&lt;/P&gt;

&lt;P&gt;your search | table event,longline,domain,ip | outputlookup yourkvstorename append=true&lt;/P&gt;

&lt;P&gt;Really awesome write up on kvstores here.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZK"&gt;http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZK&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Similar question here&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/227766/is-there-an-easy-way-to-update-a-record-in-kv-stor.html"&gt;https://answers.splunk.com/answers/227766/is-there-an-easy-way-to-update-a-record-in-kv-stor.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And a link to how you can append a kvstore.&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Outputlookup"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Outputlookup&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 20:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-KV-store-that-pulls-events-from-an-indexer/m-p/228376#M67511</guid>
      <dc:creator>dperre_splunk</dc:creator>
      <dc:date>2016-10-03T20:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a KV store that pulls events from an indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-KV-store-that-pulls-events-from-an-indexer/m-p/228377#M67512</link>
      <description>&lt;P&gt;I am still unable to add a COMMENT TEXT BOX for each event in the table. Also, I need to add a checkbox in front of each event. Please HELP!&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 18:17:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-KV-store-that-pulls-events-from-an-indexer/m-p/228377#M67512</guid>
      <dc:creator>naqviah</dc:creator>
      <dc:date>2016-10-05T18:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a KV store that pulls events from an indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-KV-store-that-pulls-events-from-an-indexer/m-p/228378#M67513</link>
      <description>&lt;P&gt;This sounds like you are trying to make something like the investigator timeline from Enterprise Security.&lt;/P&gt;

&lt;P&gt;Also what you are trying to achieve is not what KV Stores are traditionally used for. Have a look at the Splunk Java SDK. With the java sdk you can write your own dashboards and as it's JS you have a lot of flexibility with the scripting language.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 20:56:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-KV-store-that-pulls-events-from-an-indexer/m-p/228378#M67513</guid>
      <dc:creator>dperre_splunk</dc:creator>
      <dc:date>2016-10-05T20:56:19Z</dc:date>
    </item>
  </channel>
</rss>

