Getting Data In

How to use kvstore to store configurations for correlation across our technology stack?

brent_weaver
Builder

Hello all! I am struggling to fully understand kvstore and how to get at the data. I am not having any issues populating kvstore via curl ( http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZG ). The question I have is how to I get to that data? I cannot seem to put it together.

My ultimate goal is to build automatic lookups of our CloudFoundry config files to be able to correlate the ephemeral hosts in CF. Since it is such a dynamic environment I thought that I would read the config file and via a script (in really any language) write to kvstore in Splunk where it can be correlated.

Any help is MUCH appreciated!

0 Karma

woodcock
Esteemed Legend

There is an app to help you with this, Lookup File Editor App for Splunk Enterprise:

https://splunkbase.splunk.com/app/1724/

Anyway, the easiest way to get to the lookup data is to use a search like this:

|inputlookup YourLookupNameHere
0 Karma

gjanders
SplunkTrust
SplunkTrust

Whether it's a kvstore or a lookup the syntax remains the same to get the lookup working!

0 Karma

woodcock
Esteemed Legend

Yes, that is correct.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...