Splunk Search

Basic KV Store Question - Updating Thousands of Records at Once

alferone
Explorer

Hello all, 

I have a requirement to list all of our assets and show the last time they appeared in the logs of many different tools.  I wanted to use KV store for this.  We would run a search against each tool's logs and then update it's "last seen" time in the KV store for the particular asset.

I've attempted this a few ways, but I can't see to get it going.  I have the KV Store built with one column of last_seen times for one tool. But I am lost on how to update last_seen times for other tools for existing entries in the KV Store.

Any guidance would be appreciated.  Thank you!

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @alferone ,

why don't you use a summary index?

in this way you're sure to have the last updated version, you have also the previous versions and you don't have any limitation to the number of entries.

Ciao.

Giuseppe

View solution in original post

alferone
Explorer

So just to be clear, this would not be a candidate for KV Store?

0 Karma

alferone
Explorer

I was considering that initially.  Would the search be a little taxing to pull all of the different tools and times together?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @alferone ,

I don't think so, if you have a fixed frequency of data update.

I prefer a summary index for the reasons I listed in my before answer.

Ciao.

Giuseppe

0 Karma

alferone
Explorer

I'll give it a shot.  Thank you for your help!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @alferone ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

gcusello
SplunkTrust
SplunkTrust

Hi @alferone ,

why don't you use a summary index?

in this way you're sure to have the last updated version, you have also the previous versions and you don't have any limitation to the number of entries.

Ciao.

Giuseppe

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...