Reporting

How to add a single inline insert to kv store?

bjoernjensen
Contributor

Hi,

having several hundreds of searches scheduled. Depending on the result each search might have to insert (also) an entry into the kv store: all into one collection. (Im)Possible ways I am aware of:

REST
using POST on this endpoint: /storage/collections/data/mycollection could work, but since the rest search command will be one late part of each search, the rest command would not be the first search command. Therefore this approach does not work.
Another REST-thought was: I could try to embed the search within the rest search command syntactically, but this feels pretty bad in terms of maintenance.

outputlookup
with this approach I have to read the whole content of the collection, add one line, and then write it all back. This approach teems of non-scalability

Anyone?

0 Karma
1 Solution

bjoernjensen
Contributor

Missed the most obvious approach: ... | outputlookup append=true mycollection_defintion | ....

View solution in original post

0 Karma

bjoernjensen
Contributor

Missed the most obvious approach: ... | outputlookup append=true mycollection_defintion | ....

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...