Splunk Search

What is best approach to implement kv store to replace using lookups?

MousumiChowdhur
Contributor

HI!

I have two search heads in cluster and multiple lookups in Splunk but currently started facing issues of replication of knowledge bundles. After investigation, I have observed that few of the lookups are not getting replicated between the search heads. I have learnt that it's best to use kv store than using lookups but I don't have clear idea of how and when using kv store is best suitable.

Would really appreciate your suggestions and help.
Thanks!

yannK
Splunk Employee
Splunk Employee

To use a kvstore lookup, you need to have already a collection in "collections.conf"
then you can create the lookup in transforms.conf.
The difference is that the list of fields has to be predefined.

see http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/ConfigureKVstorelookups

To populate it you can use the API endpoints
or the first time you can populate it using kvstore methods, or use an outputlookup.
example

 | inputlookup myoldcsvlookup | <do some clean up if necessary> | outputlookup mynewkvstorelookupcollection

then you can use the new lookup the same way you were doing.
In a SHcluster situation, it should replicate accros with the kvstore.

0 Karma

niketn
Legend

@MousumiChowdhury, following Splunk Dev site elucidates the steps required for migrating from Lookups to KVStore.

http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZQ

Please try out and confirm.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...