Knowledge Management

How to search and compare the same data across multiple KV stores?

dteo827
Explorer

Greetings Splunk Answers,
I have 4 CSV's containing similar data (usernames, first/last names, job roles) all of which I have imported into individual KV Stores (and separate collections).
I need to search a username and see if it is any/all of the KV Stores.

Does anyone have experience searching across multiple KV Stores for the same data?

Cheers!

0 Karma
1 Solution

renjith_nair
Legend

Try

| inputlookup kv1 | inputlookup append=t kv2 | inputlookup append=t kv3 | inputlookup append=t kv4|search username=<username_to_search>

http://docs.splunk.com/Documentation/Splunk/6.2.0/SearchReference/Inputlookup

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

Try

| inputlookup kv1 | inputlookup append=t kv2 | inputlookup append=t kv3 | inputlookup append=t kv4|search username=<username_to_search>

http://docs.splunk.com/Documentation/Splunk/6.2.0/SearchReference/Inputlookup

---
What goes around comes around. If it helps, hit it with Karma 🙂

dteo827
Explorer

Many thanks, I somehow missed that in the documentation.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...