I'm running Splunk 6.4 and Splunk Enterprise Security 4.1. I have a method of populating KVStore collections remotely, validated I can see the data from the lookup definitions via inputlookup. However, it doesn't seem as if identity_manager definitions in inputs.conf work with KVStore defined lookups. Docs only mention CSV files, but I'm curious as to why it would not work with KVStore as well?
↧