Splunk Cloud Platform

Is it possible to use KV Store on Splunk Cloud to read and write values?

pgadzhev
Engager

I am trying to build a modular data input using the Splunk Add-on Builder and the input should be statefull - it should keep track of its progress.

The Splunk Add-on Builder supports such checks and they're called checkpoints. When reading the documentation it is stated that this technique employs KV Store.

However, the Splunk Cloud documentation itself states that the KV Store REST API endpoints cannot be used, which means that any script using the Splunk SDK would not be able to operate with the KV Store collections.

Am i wrong with interpreting the documentation and thinking that KV Store CRUD operations (using the REST API) are not allowed on Splunk Cloud?

If KV Store is not an option to persist state on Splunk Cloud, is there an any other way to do it?

Thanks!

SteveM-905
Loves-to-Learn

Still wondering here?

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Did you resolve this? We have a similar issue with KV store and REST API.

0 Karma

marcoscala
Builder
 
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...