Deployment Architecture

add/modify kvstore column in search head cluster environment

karn
Path Finder

I have a question about modify kvstore configuration in search head cluster environment.

 

I have created kvstore with lookup editor app from a search head instance. Now, I would like to add a new column. So, I have to modify from collections.conf right?. However, the configuration is not on SHC but search head instances. What is the best way to add a new column of kvstore?

 

Thank you

Labels (2)
0 Karma
1 Solution

PaulPanther
Motivator
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @karn ,

you could add a columns to a lookup using the Lookup Editor app, but remember to modify also the Lookup Definition.

With a csv lookup, you don't need to modify the Lookup Definition, but it's required for KV-Store lookups.

Ciao.

Giuseppe

0 Karma

karn
Path Finder

I can't see editing menu on lookup editor app , please guide me.

Karn

0 Karma

PaulPanther
Motivator

Have you tried to use the API to add the field?

KV store endpoint descriptions - Splunk Documentation

0 Karma

karn
Path Finder

it works.

curl -k -u admin:changeme https://localhost:8089/servicesNS/nobody/search/storage/collections/config/mykvstore -d "field.my_new_column=string"

 

Thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...