Splunk Search

What is best approach to implement kv store to replace using lookups?

MousumiChowdhur
Contributor

HI!

I have two search heads in cluster and multiple lookups in Splunk but currently started facing issues of replication of knowledge bundles. After investigation, I have observed that few of the lookups are not getting replicated between the search heads. I have learnt that it's best to use kv store than using lookups but I don't have clear idea of how and when using kv store is best suitable.

Would really appreciate your suggestions and help.
Thanks!

yannK
Splunk Employee
Splunk Employee

To use a kvstore lookup, you need to have already a collection in "collections.conf"
then you can create the lookup in transforms.conf.
The difference is that the list of fields has to be predefined.

see http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/ConfigureKVstorelookups

To populate it you can use the API endpoints
or the first time you can populate it using kvstore methods, or use an outputlookup.
example

 | inputlookup myoldcsvlookup | <do some clean up if necessary> | outputlookup mynewkvstorelookupcollection

then you can use the new lookup the same way you were doing.
In a SHcluster situation, it should replicate accros with the kvstore.

0 Karma

niketn
Legend

@MousumiChowdhury, following Splunk Dev site elucidates the steps required for migrating from Lookups to KVStore.

http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZQ

Please try out and confirm.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...