Getting Data In

How to use kvstore to store configurations for correlation across our technology stack?

brent_weaver
Builder

Hello all! I am struggling to fully understand kvstore and how to get at the data. I am not having any issues populating kvstore via curl ( http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZG ). The question I have is how to I get to that data? I cannot seem to put it together.

My ultimate goal is to build automatic lookups of our CloudFoundry config files to be able to correlate the ephemeral hosts in CF. Since it is such a dynamic environment I thought that I would read the config file and via a script (in really any language) write to kvstore in Splunk where it can be correlated.

Any help is MUCH appreciated!

0 Karma

woodcock
Esteemed Legend

There is an app to help you with this, Lookup File Editor App for Splunk Enterprise:

https://splunkbase.splunk.com/app/1724/

Anyway, the easiest way to get to the lookup data is to use a search like this:

|inputlookup YourLookupNameHere
0 Karma

gjanders
SplunkTrust
SplunkTrust

Whether it's a kvstore or a lookup the syntax remains the same to get the lookup working!

0 Karma

woodcock
Esteemed Legend

Yes, that is correct.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...