I have a kvstore like below populated with about 1mil rows.
| _key | name | count1 | count2 | calculated_number1 | calculated_number2 |
| sha256 hash | Joe Cool | 1 | 2 | 3 | 4 |
How can I update the kvstore where I update the two counts and recalculate the two calculated numbers based on the newly updated counts? I am trying not to read in all 1 million rows and overwrite if I dont have to.
Any potential pathways are welcome and I am here to learn. Thank you all.
With a kvstore, outputlookup command will replace the existing entry as long as you supply the original _key variable - it will not overwrite other rows if you use append=t, see example 6 here
https://docs.splunk.com/Documentation/Splunk/8.2.7/SearchReference/Outputlookup#Examples