Hello all! I am struggling to fully understand kvstore and how to get at the data. I am not having any issues populating kvstore via curl ( http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZG ). The question I have is how to I get to that data? I cannot seem to put it together.
My ultimate goal is to build automatic lookups of our CloudFoundry config files to be able to correlate the ephemeral hosts in CF. Since it is such a dynamic environment I thought that I would read the config file and via a script (in really any language) write to kvstore in Splunk where it can be correlated.
Any help is MUCH appreciated!
There is an app to help you with this, Lookup File Editor App for Splunk Enterprise
:
https://splunkbase.splunk.com/app/1724/
Anyway, the easiest way to get to the lookup data is to use a search like this:
|inputlookup YourLookupNameHere
Whether it's a kvstore or a lookup the syntax remains the same to get the lookup working!
Yes, that is correct.