---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Data storage in Splunk

# Data storage in Splunk {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure and retrieve Key-Value store lookups used by TISC during its integration with Splunk.  
{#tisc-storage-splunk__table_izm_vzw_12c__entry__2}

| Lookup | Description |
|-|-|
| tisc_kv_store | Name of the KV store where the data resides. |
| tisc_store_lookup | Name of the KV lookup to be used for searching the incoming records. |
| inputs_metadata_lookup | KV lookup that stores the status of recent executions for each configured input. Each record captures the configuration name, input name, last successful execution time, status, status message, and historical fetch date. Use this lookup to verify whether an input is running on schedule and to diagnose failures. |
| inputlookup <tisc_store_lookup>" example : | inputlookup tisc_store_lookup | Query to lookup records in the KV store. |
[ ]

{#tisc-storage-splunk__table_izm_vzw_12c}

