Getting Data In

How do I set up a KV Store lookup?

danielbb
Motivator

I created a KV Store lookup using the "Splunk App for Lookup File Editing" app, however when I look at Settings>Lookups, the lookup definition doesn't show up.  In addition, when running

| inputlookup <name>

I get the error "The lookup table '<name>' requires a .csv or KV store lookup definition"
 
What do I miss? 

Labels (1)
Tags (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

HI @danielbb 

You need to create the lookup definition once you have created the KV Store collection in the lookup editor app.

Go to Settings->Lookups->Lookup Definitions.

Create a new one as below - filling in the relevant details:

livehybrid_0-1744236260568.png

 

Then you should be able to search it using |inputlookup

Note: I generally try and call the definition something different to the collection/kv store name but you do not need to.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

PickleRick
SplunkTrust
SplunkTrust

Typically that's a result of wrong scope or insufficient access - your lookup is either private or exported only to the app you've created it in but you're searching from another app (typically the search app)

danielbb
Motivator

Thank you @PickleRick, it was a confusion about the app where the collection and the definition exist. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
This is most common issue if you don’t see and can’t use it from other options.
I’m not sure/haven’t checked I last times what options you can set with this app. In most cases with small or mid sized lookups this works (enough) well, but if you have huge ones and/or you are needing e.g. accelerations then it’s easier to define those via conf files.
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...