Dashboards & Visualizations

KV Store share among 2 SearchHeads and a Heavy fowarder

myfriendhenry
Explorer

I have DB_Connect running only on the Heavy Forwarder. (Got that working)
I want to get a single value from a database (A Date Value), store it in the KV-Store on the Heavy Forwarder (I know how to do that)
I want that Key/Value to be available to both of my (non-clustered) Search Heads. - HOW TO DO THIS?

To clarify a bit. I want to put this value in a dashboard and don't want the query run directly from it.

1. I don't want search heads accessing the database
2. This should also yield somewhat better dashboard performance.

Would like the process to be something like this:
Scheduled DBXQuery Updates K/Value on HF | HF Replicates K/Value to Search Heads | Dashboard Queries K/Value

Tags (1)
0 Karma
1 Solution

starcher
Influencer

https://splunkbase.splunk.com/app/3519/

Use that as an alert action on the the HF. Send to a kvstore on the SH.
Your search would simply be an inputlookup of the HF local lookup table with the alert action attached.

View solution in original post

0 Karma

starcher
Influencer

https://splunkbase.splunk.com/app/3519/

Use that as an alert action on the the HF. Send to a kvstore on the SH.
Your search would simply be an inputlookup of the HF local lookup table with the alert action attached.

0 Karma

myfriendhenry
Explorer

Awesome, this appears to be the missing link.

0 Karma

myfriendhenry
Explorer

100% working, thank you!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...