As of Splunk 6.2, there is a Key-Value (KV) store baked into the Splunk Search Head. The Splunk KV store leverages MongoDB under the covers and among other things, can be leveraged for lookups and state tables. Better yet, unlike regular Splunk CSV lookups, you can actually update individual rows in the lookup without rebuilding the entire lookup – pretty cool! In this article, we will show you a quick way of how you can leverage the KV store as a lookup or state table. Read more
The following blog posting provides guidance on steps that can be taken to secure and harden Splunk environments. Many of the security feature essentially follow security best practices, while others would probably only be implemented if there was a business or regulatory need to do so. Read more
So many people talk about the need to index tweets from twitter into Splunk, that I figured I would write a post to explain just how easy it is. Within 10 steps and a few minutes, you will be streaming real-time tweets into Splunk, with the fields all extracted and the twitter data fully searchable. Read more
© Copyright 2020. Discovered Intelligence Inc.
From Our Blog
- If you are a @Splunk customer and DSP doesn't get you super excited then we don't know what will! Such an exciting… https://t.co/tsHYWXBDpI 5 days ago
- RT @iam_joshd: For those Torontonians out there, the @splunk #Toronto User Group will be (virtually) meeting this Tuesday from 530… https://t.co/emfQxSYmpq 1 week ago