Getting Data In

How do we define collections.conf in SplunkCloud?

morethanyell
Builder

Creating Lookup Definition (transforms stanza) can be done on Splunk Web UI. But since we need to point a kv definition to a collections.conf, we must have that stanza in collections.conf. How do we define collections.conf in SplunkCloud? Thanks in advance.

0 Karma
1 Solution

woodcock
Esteemed Legend

You have to either deploy an app that is cloud vetted which contains one OR to create one just for you, you must open a support case.

View solution in original post

morethanyell
Builder

This problem can be solved if you have Lookup Editor installed in your SplunkCloud search head. In that app, there's a way to configure a new KV Lookup and that includes taking care of collections-conf name.

0 Karma

woodcock
Esteemed Legend

You have to either deploy an app that is cloud vetted which contains one OR to create one just for you, you must open a support case.

Luispl55
New Member

Hi Woodcock,

Do you know if this is still the case nowadays (2024)?

thanks.

 

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

it's more or less same situation. You have those three options:

  1. Use lookup editor app
  2. Create own app which contains those definition and install it. In Victoria experience you can do it by your self
  3. On Classic edition you probably still need to create a support case or create cloud vetted private app on splunkbase from where you (probably) could install it by yourself?

I said that the lookup editor app is probably the easiest way to do it unless your are familiar with your own apps and need this otherwise too.

https://splunkbase.splunk.com/app/1724

r. Ismo

0 Karma

morethanyell
Builder

sucks man 😞

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...