We can actually convert the state table we just created into a KV store table and then modify the existing scheduled search accordingly.
Here are the steps to convert the existing state table to leverage the Splunk KV store instead:
- Firstly, there is one small configuration step that we cannot do from the GUI. Create a new file called collections.conf. Into this file, enter the name of the KV collection as follows:
[session_state]
- Save this file to the following location and restart Splunk.$SPLUNK_HOME/etc/apps/operational_intelligence/local.
- Everything else can now be done from the GUI! We need to create the new KV lookup. Click on the Settings menu and then select the Lookups ...