I suggest you ...

Allow JSON to be used directly, from a file, to populate a KVstore collection.

I have a use case where the easiest, most useful method of using a kvstore collection as a lookup is by a mechanism similar to a CSV lookup. I'd like to be able to create a collection, point it at a JSON file on disk (which I will populate asynchronously outside of Splunk's purview) and have it "just work" like the CSV ones do. IT *never* needs to "update" in place, if it finds the file changed (or on a schedule I pick) just dump the old stuff and reload it.

3 votes
Vote
Sign in
Check!
(thinking…)
Reset
or sign in with
  • facebook
  • google
    Password icon
    I agree to the terms of service
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    Rich Mahlerwein / RichfezRich Mahlerwein / Richfez shared this idea  ·   ·  Admin →

    0 comments

    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      Submitting...

      Feedback and Knowledge Base