Getting Data In

How do I set up a KV Store lookup?

danielbb
Motivator

I created a KV Store lookup using the "Splunk App for Lookup File Editing" app, however when I look at Settings>Lookups, the lookup definition doesn't show up.  In addition, when running

| inputlookup <name>

I get the error "The lookup table '<name>' requires a .csv or KV store lookup definition"
 
What do I miss? 

Labels (1)
Tags (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

HI @danielbb 

You need to create the lookup definition once you have created the KV Store collection in the lookup editor app.

Go to Settings->Lookups->Lookup Definitions.

Create a new one as below - filling in the relevant details:

livehybrid_0-1744236260568.png

 

Then you should be able to search it using |inputlookup

Note: I generally try and call the definition something different to the collection/kv store name but you do not need to.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

PickleRick
SplunkTrust
SplunkTrust

Typically that's a result of wrong scope or insufficient access - your lookup is either private or exported only to the app you've created it in but you're searching from another app (typically the search app)

danielbb
Motivator

Thank you @PickleRick, it was a confusion about the app where the collection and the definition exist. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
This is most common issue if you don’t see and can’t use it from other options.
I’m not sure/haven’t checked I last times what options you can set with this app. In most cases with small or mid sized lookups this works (enough) well, but if you have huge ones and/or you are needing e.g. accelerations then it’s easier to define those via conf files.
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...