Getting Data In

How to add a CSV file to an existing kvstore?

prtrnr13
New Member

I am trying to add data to an existing kvstore. I have tried to input the data via a CSV. I'm new to Splunk and need assistance so any help is greatly appreciated. Thanks in advance.

0 Karma

starcher
SplunkTrust
SplunkTrust

Load the csv as a normal lookup. Then look at doing an inputlookup of your csv followed by an outlook up to the kvstore lookup. Co sided append=true on the outputlookup if you don't want to wipe out existing data. Talking to your splunk admin would be a good idea on the steps involved if you are new.

0 Karma

starcher
SplunkTrust
SplunkTrust

If you are more a developer you can modify a copy of this as a method to push csv content to a collection. https://github.com/georgestarcher/Splunk-ESIntel-KVStore/blob/master/splunk-es-threat-intel.py

0 Karma

prtrnr13
New Member

Thanks - I'll give it a shot.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...