All Apps and Add-ons

Splunk DB Connect: If using Output connection to insert in database, how is the Heavy Forwarder supposed to search my events in the index layer?

ahmedhassanean
Explorer

Dears,

i would like to install Splunk DB connect v3 but i have questions regarding recommended setup of it in a Heavy Forwarder. In case i am using Output connection to insert in database, how is the Heavy forwarder supposed to be able to search my events in the index layer?

thanks in advance

0 Karma
1 Solution

woodcock
Esteemed Legend

You will have to make your Heavy Forwarder a full Search Head by adding your Indexers as Search Peers (or migrate this function to your Search Head).

View solution in original post

0 Karma

woodcock
Esteemed Legend

You will have to make your Heavy Forwarder a full Search Head by adding your Indexers as Search Peers (or migrate this function to your Search Head).

0 Karma

ahmedhassanean
Explorer

agree with you but my questions is Guide already informed us to not add DB connect on SH cluster
So why they going for that they adding now extra processing to HF

0 Karma

woodcock
Esteemed Legend

These roles are just names. Make your HF a Search Head, too. Just use the GUI to add the Search Peers and that's it. It is just a name, for the most part. Do not add this stand-alone Search Head to the other SHC and DO NOT let other people login to it to run searches here.

0 Karma

eddiet
Explorer

Thanks for pointing this out.
Should really be documented. This and HEC dependency

0 Karma

woodcock
Esteemed Legend

The Heavy Forwarder is to run the DB Connect queries and then send (outputs.conf pointing to your Indexer tier) to your Indexers. The Heavy Forwarder does not "search your events" at all; it GENERATES them and stores them on the Indexers.

0 Karma

ahmedhassanean
Explorer

you are talking about Input connection which mean run query into database and send data to indexers
but i am talking about inserting data from splunk to Database through Output connection in DB connect it self
how supposed DB connect will search my events that exist in indexer tier

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...