Knowledge Management

How do I view / use my Splunk KV store collections?

SamHTexas
Builder

I looked in lookups but did not find them. How do I view / use my Splunk KV store collections?

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
Legend

Hi @SamHTexas,

as you can see at https://docs.splunk.com/Documentation/Splunk/8.1.2/Knowledge/ConfigureKVstorelookups you configure your kv-store in collections.conf and transforms.conf, then you can find them in Lookup Definitions.

Ciao.

Giuseppe

View solution in original post

gcusello
Legend

Hi @SamHTexas,

as you can see at https://docs.splunk.com/Documentation/Splunk/8.1.2/Knowledge/ConfigureKVstorelookups you configure your kv-store in collections.conf and transforms.conf, then you can find them in Lookup Definitions.

Ciao.

Giuseppe

SamHTexas
Builder

Thank u as always. Just a crazy question please? What is your method of editing / viewing the .cong files. Are they only viewed & edited via CLI 100% of the time? Is any editing or viewing of the .conf files done via GUI ? 

Tags (1)
0 Karma

gcusello
Legend

Hi @SamHTexas,

I'm not so sure but I think that I edit conf files maily via CLI, maybe not 100% but a near number!

I use GUI sometimes mainly in test on my PC, but at this moment I don't remember something that i do via GUI, especially on production systems, also why clusters (SHs and INDs), deployment servers, props.conf and transforms.con are difficoult to modify via GUI, maybe something on props, but I don't remember and this means that it's very rare.

Ciao and happy splunking.

Giuseppe

0 Karma

SamHTexas
Builder

Garzie for your answer. What is the path to the collections.conf and transforms.com ( where are they found) ? Thank u

Tags (1)
0 Karma

gcusello
Legend

Hi @SamHTexas,

as all the App's configuration files, they are in the local folder of your App.

Ciao.

Giuseppe

P.S.: If this answer solves your need, please, accept it for the other people of Community and Karma Points are appreciated 😉

Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...