All Apps and Add-ons

Importing KV store values from ITSI to a lookup file in splunk


Hey guys,
There is a certain mapping present between two multi-valued variables inside ITSI , I would like to use this mapping as a lookup in splunk.
Is there any way I can get this mapping into splunk in lookup tables, so that I can just use inputlookup command to get the mapping table.
I believe the config files are involved in this process and if so how do I access these files. Can someone point me in the right direction please. I am new to splunk
Thank you.

0 Karma

Splunk Employee
Splunk Employee

This document covers how to use lookups with KV Store data, including use with the inputlookup command:

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>