Knowledge Management

KV Store Update Multiple Records


Quick question about KV store - wondering what the best way to update multiple records at once via search may be?

Example - let's say I have the most recent logon for users for the past week:

user1 - lastlogontime
user2 - lastlogontime

I would like to query lastlogontime for all users for the past day, then update the KV store with the most recent info. The goal would be to set this up as a schedule search running daily to keep the KV store updated.

Any thoughts?

Labels (1)
0 Karma

Re: KV Store Update Multiple Records



Can you please share your existing sample search/ code for updating KVStore and the sample KVstore fields?

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.