Creating Lookup Definition (transforms stanza) can be done on Splunk Web UI. But since we need to point a kv definition to a collections.conf, we must have that stanza in collections.conf. How do we define collections.conf in SplunkCloud? Thanks in advance.
You have to either deploy an app that is cloud vetted
which contains one OR to create one just for you, you must open a support case.
This problem can be solved if you have Lookup Editor installed in your SplunkCloud search head. In that app, there's a way to configure a new KV Lookup and that includes taking care of collections-conf name.
You have to either deploy an app that is cloud vetted
which contains one OR to create one just for you, you must open a support case.
Hi Woodcock,
Do you know if this is still the case nowadays (2024)?
thanks.
Hi
it's more or less same situation. You have those three options:
I said that the lookup editor app is probably the easiest way to do it unless your are familiar with your own apps and need this otherwise too.
https://splunkbase.splunk.com/app/1724
r. Ismo
sucks man 😞