Knowledge Management

How do I view / use my Splunk KV store collections?

SamHTexas
Builder

I looked in lookups but did not find them. How do I view / use my Splunk KV store collections?

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

as you can see at https://docs.splunk.com/Documentation/Splunk/8.1.2/Knowledge/ConfigureKVstorelookups you configure your kv-store in collections.conf and transforms.conf, then you can find them in Lookup Definitions.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

as you can see at https://docs.splunk.com/Documentation/Splunk/8.1.2/Knowledge/ConfigureKVstorelookups you configure your kv-store in collections.conf and transforms.conf, then you can find them in Lookup Definitions.

Ciao.

Giuseppe

SamHTexas
Builder

Thank u as always. Just a crazy question please? What is your method of editing / viewing the .cong files. Are they only viewed & edited via CLI 100% of the time? Is any editing or viewing of the .conf files done via GUI ? 

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

I'm not so sure but I think that I edit conf files maily via CLI, maybe not 100% but a near number!

I use GUI sometimes mainly in test on my PC, but at this moment I don't remember something that i do via GUI, especially on production systems, also why clusters (SHs and INDs), deployment servers, props.conf and transforms.con are difficoult to modify via GUI, maybe something on props, but I don't remember and this means that it's very rare.

Ciao and happy splunking.

Giuseppe

0 Karma

SamHTexas
Builder

Garzie for your answer. What is the path to the collections.conf and transforms.com ( where are they found) ? Thank u

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

as all the App's configuration files, they are in the local folder of your App.

Ciao.

Giuseppe

P.S.: If this answer solves your need, please, accept it for the other people of Community and Karma Points are appreciated 😉

Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...