Getting Data In

How to use kvstore to store configurations for correlation across our technology stack?

brent_weaver
Builder

Hello all! I am struggling to fully understand kvstore and how to get at the data. I am not having any issues populating kvstore via curl ( http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZG ). The question I have is how to I get to that data? I cannot seem to put it together.

My ultimate goal is to build automatic lookups of our CloudFoundry config files to be able to correlate the ephemeral hosts in CF. Since it is such a dynamic environment I thought that I would read the config file and via a script (in really any language) write to kvstore in Splunk where it can be correlated.

Any help is MUCH appreciated!

0 Karma

woodcock
Esteemed Legend

There is an app to help you with this, Lookup File Editor App for Splunk Enterprise:

https://splunkbase.splunk.com/app/1724/

Anyway, the easiest way to get to the lookup data is to use a search like this:

|inputlookup YourLookupNameHere
0 Karma

gjanders
SplunkTrust
SplunkTrust

Whether it's a kvstore or a lookup the syntax remains the same to get the lookup working!

0 Karma

woodcock
Esteemed Legend

Yes, that is correct.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...