Knowledge Management

How do I view / use my Splunk KV store collections?

SamHTexas
Builder

I looked in lookups but did not find them. How do I view / use my Splunk KV store collections?

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

as you can see at https://docs.splunk.com/Documentation/Splunk/8.1.2/Knowledge/ConfigureKVstorelookups you configure your kv-store in collections.conf and transforms.conf, then you can find them in Lookup Definitions.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

as you can see at https://docs.splunk.com/Documentation/Splunk/8.1.2/Knowledge/ConfigureKVstorelookups you configure your kv-store in collections.conf and transforms.conf, then you can find them in Lookup Definitions.

Ciao.

Giuseppe

SamHTexas
Builder

Thank u as always. Just a crazy question please? What is your method of editing / viewing the .cong files. Are they only viewed & edited via CLI 100% of the time? Is any editing or viewing of the .conf files done via GUI ? 

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

I'm not so sure but I think that I edit conf files maily via CLI, maybe not 100% but a near number!

I use GUI sometimes mainly in test on my PC, but at this moment I don't remember something that i do via GUI, especially on production systems, also why clusters (SHs and INDs), deployment servers, props.conf and transforms.con are difficoult to modify via GUI, maybe something on props, but I don't remember and this means that it's very rare.

Ciao and happy splunking.

Giuseppe

0 Karma

SamHTexas
Builder

Garzie for your answer. What is the path to the collections.conf and transforms.com ( where are they found) ? Thank u

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

as all the App's configuration files, they are in the local folder of your App.

Ciao.

Giuseppe

P.S.: If this answer solves your need, please, accept it for the other people of Community and Karma Points are appreciated 😉

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...