All Apps and Add-ons

Importing KV store values from ITSI to a lookup file in splunk

pkol
Explorer

Hey guys,
There is a certain mapping present between two multi-valued variables inside ITSI , I would like to use this mapping as a lookup in splunk.
Is there any way I can get this mapping into splunk in lookup tables, so that I can just use inputlookup command to get the mapping table.
I believe the config files are involved in this process and if so how do I access these files. Can someone point me in the right direction please. I am new to splunk
Thank you.

0 Karma

mdonnelly_splun
Splunk Employee
Splunk Employee

This document covers how to use lookups with KV Store data, including use with the inputlookup command:
http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZH

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...