Splunk Enterprise

KV Store not updated by Outputlookup

_Tom
Explorer

We have a saved search in a search head cluster which returns its results in a KV-Store lookup using append=true.
Although the searches run successfully, the results where not stored in the KV-Store for few executions.
Unfortunately, we were not able to locate the issue in the mongod.log or splunkd.log.
Any ideas are appreciated.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...