Getting Data In

How to add a CSV file to an existing kvstore?

prtrnr13
New Member

I am trying to add data to an existing kvstore. I have tried to input the data via a CSV. I'm new to Splunk and need assistance so any help is greatly appreciated. Thanks in advance.

0 Karma

starcher
Influencer

Load the csv as a normal lookup. Then look at doing an inputlookup of your csv followed by an outlook up to the kvstore lookup. Co sided append=true on the outputlookup if you don't want to wipe out existing data. Talking to your splunk admin would be a good idea on the steps involved if you are new.

0 Karma

starcher
Influencer

If you are more a developer you can modify a copy of this as a method to push csv content to a collection. https://github.com/georgestarcher/Splunk-ESIntel-KVStore/blob/master/splunk-es-threat-intel.py

0 Karma

prtrnr13
New Member

Thanks - I'll give it a shot.

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...