Splunk Search

Can Splunk pull *the contents* of a lookup created in a search head cluster via rest command search into a non-cluster search-head?

Path Finder

I created a Splunk Health Dashboard for myself on the server that runs my Monitoring Console. The MC server is not part of my search head cluster. My search head cluster updates a lookup every hour that gets service account status that I'd like to add to my custom dashboard on my Monitoring Console. Is there a way to get the contents of the lookup in the search head cluster into a search on my Monitoring Console?



If you make a kvstore lookup to land in

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!