Hello Splunkers! We have a situation here and need your help and experience. We are looking for best practice to work with Large CSV files (1Million Rows at least) to produce fast searches a...
Creating LookupDefinition (transforms stanza) can be done on SplunkWeb UI. But since we need to point akvdefinition to a collections.conf, we must have that stanza in collections.conf. How do w...
I am setting up permissions for kvstore collections.
I tried to give permission in local.meta in my app for all the collections, but still getting
" Error in 'outputlookup' command: the lookup...
Has anyone figured a way to make kv-storelookups NOT case sensitive on field values? If so, how?
We're about to migrate users to a new search head cluster where all large (> 20 MB) public lookup...
Hi splunkers,
I need to enrich the Checkpoint Firewall logs with the username in my corporate VPN logs.
On a first sourcetype, I have the name of the user with his DHCP IP address in the VPN (f...
I created a test KVStore in order to familiarize myself with the API. It has about 20 records in it, all of which are listed under the user nobody (viewable from search). However, when running |in...
how can i combine queries to populate alookup table?
I have alookup table with the following values
item
1
2
3
i'm using the splunkweb framework to allow a user to insert an item....
...he manually edited data on alookup table (csv), join those fields to my search, and present it in my table. I tried to think about a way of letting the user edit those fields, so I setted a d...
Hello all,
We are having some problems defining a time-based kvstore lookup on Splunk 6.2.0.
We tried defining a similar time_based csv lookupand it works!
kvstore time-based lookupdefin...