All Apps and Add-ons

importing data to existing splunk kv store using lookup editor causing issues

sanjeev543
Communicator

I am trying to bulk edit the KV store lookup by exporting as CSV using lookup editor, once I make changes to the data fields (not modifying _key) and importing the same file using lookup editor causing data to be appended to the existing KV Store and it generating new _key values for the data.
Is there a way to restrict this behavior of lookup editor? @LukeMurphey

0 Karma
1 Solution

LukeMurphey
Champion

There isn't yet. I opened a ticket to add the capability to prevent duplication when the _key already exists. See https://lukemurphey.net/issues/2594

View solution in original post

0 Karma

LukeMurphey
Champion

There isn't yet. I opened a ticket to add the capability to prevent duplication when the _key already exists. See https://lukemurphey.net/issues/2594

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...