<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk DB Connect: If two Splunk servers create a database input from TableA, will this cause duplicates to be indexed? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DB-Connect-If-two-Splunk-servers-create-a-database-input/m-p/170798#M23273</link>
    <description>&lt;P&gt;If two Splunk server create a Database input from table A, will this cause any conflict? Will both Server1 and Server2 import to index if a new record is inserted into table A?&lt;/P&gt;</description>
    <pubDate>Mon, 09 Mar 2015 07:28:36 GMT</pubDate>
    <dc:creator>oraclebox</dc:creator>
    <dc:date>2015-03-09T07:28:36Z</dc:date>
    <item>
      <title>Splunk DB Connect: If two Splunk servers create a database input from TableA, will this cause duplicates to be indexed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DB-Connect-If-two-Splunk-servers-create-a-database-input/m-p/170798#M23273</link>
      <description>&lt;P&gt;If two Splunk server create a Database input from table A, will this cause any conflict? Will both Server1 and Server2 import to index if a new record is inserted into table A?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2015 07:28:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DB-Connect-If-two-Splunk-servers-create-a-database-input/m-p/170798#M23273</guid>
      <dc:creator>oraclebox</dc:creator>
      <dc:date>2015-03-09T07:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect: If two Splunk servers create a database input from TableA, will this cause duplicates to be indexed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DB-Connect-If-two-Splunk-servers-create-a-database-input/m-p/170799#M23274</link>
      <description>&lt;P&gt;you'll get a duplicate copy of your table.&lt;BR /&gt;
DB1.TableA -&amp;gt; SplunkX.Input1A -&amp;gt; Index1&lt;BR /&gt;
DB1.TableA -&amp;gt; SplunkY.Input1A -&amp;gt; Index1&lt;/P&gt;

&lt;P&gt;Index1 now contains:&lt;BR /&gt;
DB1.TableA.Row1&lt;BR /&gt;
DB1.TableA.Row1&lt;BR /&gt;
DB1.TableA.Row2&lt;BR /&gt;
DB1.TableA.Row2&lt;BR /&gt;
et cetera et cetera&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2015 16:53:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DB-Connect-If-two-Splunk-servers-create-a-database-input/m-p/170799#M23274</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-03-09T16:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect: If two Splunk servers create a database input from TableA, will this cause duplicates to be indexed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DB-Connect-If-two-Splunk-servers-create-a-database-input/m-p/170800#M23275</link>
      <description>&lt;P&gt;Yes, both Splunk inputs will grab the same [full] set of data, though perhaps at different times.  Inputs like these should be independent.  See below for more explanation.&lt;/P&gt;

&lt;P&gt;Assume you have a DB input on Splunk Server 1 that gets its input from, say, DBServerA, TableX.  Then another DB input on Splunk Server 2 that gets its input from DBServerA, TableX as well.&lt;/P&gt;

&lt;P&gt;Each Splunk server runs a SQL Query like &lt;CODE&gt;select * from TableX {{ where $rising_column$ &amp;gt; ?}}&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;The first time through, the {{ ... }} is left off so the input can grab all the data.  After that, each Splunk server will remember the last value for whatever has been declared as the $rising_column$ and use that for subsequent queries.  Therefore, each server will get a copy of all rows that are newer than the last row that server had last requested, regardless of what other queries may have happened in the interim (applications, other Splunk servers, etc...)&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2015 17:01:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DB-Connect-If-two-Splunk-servers-create-a-database-input/m-p/170800#M23275</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2015-03-09T17:01:38Z</dc:date>
    </item>
  </channel>
</rss>

