Knowledge Management

How do I view / use my Splunk KV store collections?

SamHTexas
Builder

I looked in lookups but did not find them. How do I view / use my Splunk KV store collections?

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
Esteemed Legend

Hi @SamHTexas,

as you can see at https://docs.splunk.com/Documentation/Splunk/8.1.2/Knowledge/ConfigureKVstorelookups you configure your kv-store in collections.conf and transforms.conf, then you can find them in Lookup Definitions.

Ciao.

Giuseppe

View solution in original post

gcusello
Esteemed Legend

Hi @SamHTexas,

as you can see at https://docs.splunk.com/Documentation/Splunk/8.1.2/Knowledge/ConfigureKVstorelookups you configure your kv-store in collections.conf and transforms.conf, then you can find them in Lookup Definitions.

Ciao.

Giuseppe

SamHTexas
Builder

Thank u as always. Just a crazy question please? What is your method of editing / viewing the .cong files. Are they only viewed & edited via CLI 100% of the time? Is any editing or viewing of the .conf files done via GUI ? 

Tags (1)
0 Karma

gcusello
Esteemed Legend

Hi @SamHTexas,

I'm not so sure but I think that I edit conf files maily via CLI, maybe not 100% but a near number!

I use GUI sometimes mainly in test on my PC, but at this moment I don't remember something that i do via GUI, especially on production systems, also why clusters (SHs and INDs), deployment servers, props.conf and transforms.con are difficoult to modify via GUI, maybe something on props, but I don't remember and this means that it's very rare.

Ciao and happy splunking.

Giuseppe

0 Karma

SamHTexas
Builder

Garzie for your answer. What is the path to the collections.conf and transforms.com ( where are they found) ? Thank u

Tags (1)
0 Karma

gcusello
Esteemed Legend

Hi @SamHTexas,

as all the App's configuration files, they are in the local folder of your App.

Ciao.

Giuseppe

P.S.: If this answer solves your need, please, accept it for the other people of Community and Karma Points are appreciated 😉

Get Updates on the Splunk Community!

Set Up More Secure Configurations in Splunk Enterprise With Config Assist

This blog post is part 3 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...