Splunk Search

Can Splunk pull *the contents* of a lookup created in a search head cluster via rest command search into a non-cluster search-head?

esalesapns2
Communicator

I created a Splunk Health Dashboard for myself on the server that runs my Monitoring Console. The MC server is not part of my search head cluster. My search head cluster updates a lookup every hour that gets service account status that I'd like to add to my custom dashboard on my Monitoring Console. Is there a way to get the contents of the lookup in the search head cluster into a search on my Monitoring Console?

starcher
Influencer

https://splunkbase.splunk.com/app/3519/

If you make a kvstore lookup to land in

0 Karma
Get Updates on the Splunk Community!

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...