Deployment Architecture

add/modify kvstore column in search head cluster environment

karn
Path Finder

I have a question about modify kvstore configuration in search head cluster environment.

 

I have created kvstore with lookup editor app from a search head instance. Now, I would like to add a new column. So, I have to modify from collections.conf right?. However, the configuration is not on SHC but search head instances. What is the best way to add a new column of kvstore?

 

Thank you

Labels (2)
0 Karma
1 Solution

PaulPanther
Motivator
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @karn ,

you could add a columns to a lookup using the Lookup Editor app, but remember to modify also the Lookup Definition.

With a csv lookup, you don't need to modify the Lookup Definition, but it's required for KV-Store lookups.

Ciao.

Giuseppe

0 Karma

karn
Path Finder

I can't see editing menu on lookup editor app , please guide me.

Karn

0 Karma

PaulPanther
Motivator

Have you tried to use the API to add the field?

KV store endpoint descriptions - Splunk Documentation

0 Karma

karn
Path Finder

it works.

curl -k -u admin:changeme https://localhost:8089/servicesNS/nobody/search/storage/collections/config/mykvstore -d "field.my_new_column=string"

 

Thanks

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...