Splunk Search

How to switch the CMDB lookups in splunk to the KV store ?

srampally
Path Finder

We currently have lookups and want to move to KV store. What and how can we do that

Tags (1)

lekanneer
Loves-to-Learn Lots

If you're looking for an efficient and functional ServiceNow to Splunk integration (also CMDB) take a look at: https://www.thedutchdatadifference.nl/splunk-servicenow/

I created that solution and continuously adding new features. One of the use cases I have done is comparing data available in Splunk with what is in CMDB.

0 Karma

woodcock
Esteemed Legend

Are you using ES or your own custom search environment?

0 Karma

srampally
Path Finder

we are using ES

0 Karma

woodcock
Esteemed Legend

So far as I know, this is not supported. What is prompting your move to KV Store? Are you in SHC? If so, then a move to KV Store is suicide anyway.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...