I have begun to accumulate some reference information about my company's AWS environment based on a bunch of queries. Things like what accounts and VPCs, we have and when they were first seen (among other info). Been happily accumulating this data into lookup tables, but now I realize that users on another Search Head Cluster would benefit from what I am doing on my SHC (which is reserved for Splunk ES)
Lookup tables don't cut it anymore since they are maintained on the SHC so their data is not available to the other SHC.
Is there a best practice on how to maintain such data so that it can be accessed from 2+ SHCs?
Some solutions that I can think of:
are there other ways to approach what I want?
(I'm really hoping that there is an answer like "you can make a KV store on the indexer")
Thanks, that is certainly among possible solutions, but unfortunately not available to me.
I do not have access to the box, so I cannot set up rsync on a file. Also my PS consultant has bemoaned that she is not allowed to use rsync in our AWS environment.