Getting Data In

How to use kvstore to store configurations for correlation across our technology stack?

brent_weaver
Builder

Hello all! I am struggling to fully understand kvstore and how to get at the data. I am not having any issues populating kvstore via curl ( http://dev.splunk.com/view/webframework-developapps/SP-CAAAEZG ). The question I have is how to I get to that data? I cannot seem to put it together.

My ultimate goal is to build automatic lookups of our CloudFoundry config files to be able to correlate the ephemeral hosts in CF. Since it is such a dynamic environment I thought that I would read the config file and via a script (in really any language) write to kvstore in Splunk where it can be correlated.

Any help is MUCH appreciated!

0 Karma

woodcock
Esteemed Legend

There is an app to help you with this, Lookup File Editor App for Splunk Enterprise:

https://splunkbase.splunk.com/app/1724/

Anyway, the easiest way to get to the lookup data is to use a search like this:

|inputlookup YourLookupNameHere
0 Karma

gjanders
SplunkTrust
SplunkTrust

Whether it's a kvstore or a lookup the syntax remains the same to get the lookup working!

0 Karma

woodcock
Esteemed Legend

Yes, that is correct.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...