Splunk Search

Writing records to KVStore - Strange Behavior

prashantsreeniv
Observer

Hello

Am attempting to identify the name of the SQL Server and the SQL Agent process name based on a CMDB lookup and storing them into a KVStore.

The results from the SPL itself show the correct results, however when checking the KVStore, its found that only the process name related to the Agent gets stored.

On filtering the results, am able to store the Server process name, but when running without filters only the Agent process name is stored.

SPL last lines -

| inputlookup append=true lookup_host_process_monitoring_list
| dedup process snow_node
| outputlookup lookup_host_process_monitoring_list

Results from execution -

SPL Output.png

 

Result stored in KVStore -

KVStore Result.png

 

If the same SPL, I send the output to a CSV, all the results get saved.

Has anyone seen or come across a similar situation? 

Thanks n regards

Prashant

Labels (1)
0 Karma

lekanneer
Loves-to-Learn Lots

This is why I developed a solution to overcome the problem of lookups and/or indexes and/or complex searches. My solution is using a Neo4j graph database in between the source of the information and Splunk. The good thing of the graph database is that it is capable of searching for relationships or the lack of relationships. So you can even combine several sources to give you the context that you need.

I'm triggered for the CMDB word. And with my solution it becomes much much more easy.

I wrote a post about that recently: SOCs: why they struggle with context 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...