Splunk Search

Add automatic lookup for kvstore?

Shakira1
Explorer

I have kvstore which generate the data by API. 

when I use | lookup  mylookup id output data - its working

I want to convert it to automatic lookup in some index, but its not working.

any idea why?

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Shakira1 ,

whad do you mean with "it's not working"? what's the bahavior?

did you created the lookup definition?

Could you share the related conf files (transforms.conf)?

Ciao.

Giuseppe

0 Karma

Shakira1
Explorer

The purpose is to enrichment the data automatically 

I did it in the UI under automatic lookup:

my lookup id AS id OUTPUT my fields_from_the_lookups

it always working but the diff here is that I'm using KVstore 

 

thanks

 

0 Karma

yuanliu
SplunkTrust
SplunkTrust

I'm not sure if I follow.  This is the UI under Automatic Lookup.

kvstore lookup.png

Can you illustrate how each field is populated? (Anonymize as needed.)

0 Karma

Shakira1
Explorer

Shakira1_0-1678874425397.png

this one?  this is working for me in SPL

and I add automatic lookup - which not working ( didnt extract the fields) 

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Not sure where the confusion is, but no box in Advanced options accepts an expression like "| lookup  mylookup id output data". (Define a KV Store lookup in Splunk Web.)  Or maybe I just didn't get what the problem was.

Maybe you can explain/illustrate/screenshot how you "convert it to automatic lookup in some index"; in addition, what is "it" that you are trying to convert?  Also, "not working" conveys little information in the best of situations.  You need to explain the data set (including event format in the index), what fields are extracted at index time, what fields are extracted automatically at search time, etc.  In particular, how is the field id obtained when you use that SPL?  For example, calculated fields cannot be used in automatic lookup. The sequence of search-time operations is full of such nuances.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...