Knowledge Management
Highlighted

KV Store Update Multiple Records

Explorer

Quick question about KV store - wondering what the best way to update multiple records at once via search may be?

Example - let's say I have the most recent logon for users for the past week:

user1 - lastlogontime
user2 - lastlogontime
etc....

I would like to query lastlogontime for all users for the past day, then update the KV store with the most recent info. The goal would be to set this up as a schedule search running daily to keep the KV store updated.

Any thoughts?

Labels (1)
0 Karma
Highlighted

Re: KV Store Update Multiple Records

SplunkTrust
SplunkTrust

@kdroddy

Can you please share your existing sample search/ code for updating KVStore and the sample KVstore fields?

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.