Splunk Search

How to switch the CMDB lookups in splunk to the KV store ?

srampally
Path Finder

We currently have lookups and want to move to KV store. What and how can we do that

Tags (1)

lekanneer
Loves-to-Learn Lots

If you're looking for an efficient and functional ServiceNow to Splunk integration (also CMDB) take a look at: https://www.thedutchdatadifference.nl/splunk-servicenow/

I created that solution and continuously adding new features. One of the use cases I have done is comparing data available in Splunk with what is in CMDB.

0 Karma

woodcock
Esteemed Legend

Are you using ES or your own custom search environment?

0 Karma

srampally
Path Finder

we are using ES

0 Karma

woodcock
Esteemed Legend

So far as I know, this is not supported. What is prompting your move to KV Store? Are you in SHC? If so, then a move to KV Store is suicide anyway.

0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...

Enterprise Security Content Update (ESCU) | New Releases

In March, the Splunk Threat Research Team had 2 releases of security content via the Enterprise Security ...