Splunk Search

How to migrate from CSV to KV store?

tsawant
New Member

I am trying to migrate from CSV to KV store following these steps:

  1. Created collection.conf on the host in apps local directory as following:

[KV_collection]
enforceTypes = true
field.fieldname = string
field.fieldname = number
field.fieldname = number
field.fieldname = string
...

  1. Created transform.conf on the host in apps local directory as following:

[KV_lookup]
external_type = kvstore
collection = KV_collection
fields_list = fieldname1, fieldname2...

  1. Used following command to migrate from exciting CSV to KV store

| inputlookup lookup_tabl.csv | outputlookup KV_lookup

But getting error:
Error in 'outputlookup' command: The lookup table 'Permission denied for collection 'KV_collection'' is invalid

Can anyone help me where is the problem exactly?
Do I need any special permission to access the collection?
Also where can I find these collections that are created ?

0 Karma

Atchyuth_P
Path Finder

Hi @tsawant 

Please try to check the lookup definition permission whether it is in private or app.

 

Hoping this will resolve the issue

0 Karma

duartet
Path Finder

The file name should be collections.conf instead of collection.conf

0 Karma

spyme72
Path Finder

The KVStore could be present inside an app and you may be running the search from search app.
The search is not able to reach the kvstore. try running the search from the app where the kvstore is created.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...