Deployment Architecture

add/modify kvstore column in search head cluster environment

karn
Path Finder

I have a question about modify kvstore configuration in search head cluster environment.

 

I have created kvstore with lookup editor app from a search head instance. Now, I would like to add a new column. So, I have to modify from collections.conf right?. However, the configuration is not on SHC but search head instances. What is the best way to add a new column of kvstore?

 

Thank you

Labels (2)
0 Karma
1 Solution

PaulPanther
Motivator
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @karn ,

you could add a columns to a lookup using the Lookup Editor app, but remember to modify also the Lookup Definition.

With a csv lookup, you don't need to modify the Lookup Definition, but it's required for KV-Store lookups.

Ciao.

Giuseppe

0 Karma

karn
Path Finder

I can't see editing menu on lookup editor app , please guide me.

Karn

0 Karma

PaulPanther
Motivator

Have you tried to use the API to add the field?

KV store endpoint descriptions - Splunk Documentation

0 Karma

karn
Path Finder

it works.

curl -k -u admin:changeme https://localhost:8089/servicesNS/nobody/search/storage/collections/config/mykvstore -d "field.my_new_column=string"

 

Thanks

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...