All Apps and Add-ons

Splunk DB Connect: If using Output connection to insert in database, how is the Heavy Forwarder supposed to search my events in the index layer?

ahmedhassanean
Explorer

Dears,

i would like to install Splunk DB connect v3 but i have questions regarding recommended setup of it in a Heavy Forwarder. In case i am using Output connection to insert in database, how is the Heavy forwarder supposed to be able to search my events in the index layer?

thanks in advance

0 Karma
1 Solution

woodcock
Esteemed Legend

You will have to make your Heavy Forwarder a full Search Head by adding your Indexers as Search Peers (or migrate this function to your Search Head).

View solution in original post

0 Karma

woodcock
Esteemed Legend

You will have to make your Heavy Forwarder a full Search Head by adding your Indexers as Search Peers (or migrate this function to your Search Head).

0 Karma

ahmedhassanean
Explorer

agree with you but my questions is Guide already informed us to not add DB connect on SH cluster
So why they going for that they adding now extra processing to HF

0 Karma

woodcock
Esteemed Legend

These roles are just names. Make your HF a Search Head, too. Just use the GUI to add the Search Peers and that's it. It is just a name, for the most part. Do not add this stand-alone Search Head to the other SHC and DO NOT let other people login to it to run searches here.

0 Karma

eddiet
Explorer

Thanks for pointing this out.
Should really be documented. This and HEC dependency

0 Karma

woodcock
Esteemed Legend

The Heavy Forwarder is to run the DB Connect queries and then send (outputs.conf pointing to your Indexer tier) to your Indexers. The Heavy Forwarder does not "search your events" at all; it GENERATES them and stores them on the Indexers.

0 Karma

ahmedhassanean
Explorer

you are talking about Input connection which mean run query into database and send data to indexers
but i am talking about inserting data from splunk to Database through Output connection in DB connect it self
how supposed DB connect will search my events that exist in indexer tier

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...