Can any one help? I am trying to configure a KVStorelookup, I have followed the online documentation: https://docs.splunk.com/Documentation/Splunk/8.1.3/Knowledge/Configure...
Good day
Is it possible to configure MS AD objects to use kvstore for the lookup file instead of CSV ? We have a very large AD environment and lookups take up more space and time to sync with t...
...removed all existing file-based lookups.
changed searches in savedsearch.conf to populate KVStore instead of a traditional lookup.
I am able to configure & use KVStore without any issue....
...ption to use a KVstore for assets & identities? Or a way to update them with a diff, rather than pushing the entire lookup? Is there a memory requirement for a certain number of assets &a...
...y_lookup.csv OR | inputlookup my_lookup
However, when my users attempts to run the search above, they get the following errors: -"The lookup table 'my_lookup.csv' requires a .csv or KVstorelookup d...
Hello Folks, How can i perform a CIDR/Subnet match with the "ip_intel" lookup file that comes by default ? This lookupKVstore dataset has CIDR ranges and single IP's listed under "IP" c...
...019-03-09 44
I need to either configure this lookup file or possibly a KVstore in order for me to be able to pull the app values in a search by a given hour period, day, week, month, year to d...
Hi Team, I have created a lookup and KVstore in the deployer, when I execute the below bundle push command, the lookups and kvstore are not getting pushed to search heads. ./splunk apply s...
The TA ships with automatic lookup on sourcetype 'threat'.
This automatic lookup is based on KV_Store lookup.
After installing the TA, we get on every search the following warning from i...