Getting Data In

How do I set up a KV Store lookup?

danielbb
Motivator

I created a KV Store lookup using the "Splunk App for Lookup File Editing" app, however when I look at Settings>Lookups, the lookup definition doesn't show up.  In addition, when running

| inputlookup <name>

I get the error "The lookup table '<name>' requires a .csv or KV store lookup definition"
 
What do I miss? 

Labels (1)
Tags (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

HI @danielbb 

You need to create the lookup definition once you have created the KV Store collection in the lookup editor app.

Go to Settings->Lookups->Lookup Definitions.

Create a new one as below - filling in the relevant details:

livehybrid_0-1744236260568.png

 

Then you should be able to search it using |inputlookup

Note: I generally try and call the definition something different to the collection/kv store name but you do not need to.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

PickleRick
SplunkTrust
SplunkTrust

Typically that's a result of wrong scope or insufficient access - your lookup is either private or exported only to the app you've created it in but you're searching from another app (typically the search app)

danielbb
Motivator

Thank you @PickleRick, it was a confusion about the app where the collection and the definition exist. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
This is most common issue if you don’t see and can’t use it from other options.
I’m not sure/haven’t checked I last times what options you can set with this app. In most cases with small or mid sized lookups this works (enough) well, but if you have huge ones and/or you are needing e.g. accelerations then it’s easier to define those via conf files.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...