Splunk Enterprise

KV Store not updated by Outputlookup

_Tom
Explorer

We have a saved search in a search head cluster which returns its results in a KV-Store lookup using append=true.
Although the searches run successfully, the results where not stored in the KV-Store for few executions.
Unfortunately, we were not able to locate the issue in the mongod.log or splunkd.log.
Any ideas are appreciated.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...