Deployment Architecture

Is there a way to propagate dbquery result to all search heads?

joeldavideng
Path Finder

I am running a daily query against an external database that provides a list of assets that many of my searches utilize. The searches exist on multiple search heads and I would like to avoid having to install DB Connect on all of them and replicate the expensive search. Is there a way to have the query run once on a centralized node and then have the others pull this list on a daily basis without having to use the deployment server?

0 Karma
1 Solution

starcher
Influencer

Run DBX on a heavy forwarder. Have your query send to a kvstore lookup on the target SHs or SHC using the alert action in: https://splunkbase.splunk.com/app/3519/

View solution in original post

starcher
Influencer

Run DBX on a heavy forwarder. Have your query send to a kvstore lookup on the target SHs or SHC using the alert action in: https://splunkbase.splunk.com/app/3519/

joeldavideng
Path Finder

This app is fire. Thanks a lot!

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...