Use the Splunk KV store to maintain the session state table

We can actually convert the state table we just created into a KV store table and then modify the existing scheduled search accordingly.

Here are the steps to convert the existing state table to leverage the Splunk KV store instead:

  1. Firstly, there is one small configuration step that we cannot do from the GUI. Create a new file called collections.conf. Into this file, enter the name of the KV collection as follows:
[session_state]
  1. Save this file to the following location and restart Splunk.$SPLUNK_HOME/etc/apps/operational_intelligence/local.
  2. Everything else can now be done from the GUI! We need to create the new KV lookup. Click on the Settings menu and then select the Lookups ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.