Splunk Search

Can Splunk pull *the contents* of a lookup created in a search head cluster via rest command search into a non-cluster search-head?

esalesapns2
Communicator

I created a Splunk Health Dashboard for myself on the server that runs my Monitoring Console. The MC server is not part of my search head cluster. My search head cluster updates a lookup every hour that gets service account status that I'd like to add to my custom dashboard on my Monitoring Console. Is there a way to get the contents of the lookup in the search head cluster into a search on my Monitoring Console?

starcher
Influencer

https://splunkbase.splunk.com/app/3519/

If you make a kvstore lookup to land in

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...