<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk DB connect in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-DB-connect/m-p/449636#M171407</link>
    <description>&lt;P&gt;Hi Currently we have Splunk db connect installed on heavy forwarder and we have inputs configured on heavy forwarder version 3. Where we have outputs setup on search head that used some spl query to run. I want to use outputs setup on heavy forwarder but when i run those splu queries i am not getting any data , is their any way that i can make my heavy forwarder talk to my search heads to get the data or which is recommended to use outputs on heavy forwarder or in search heads ?&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2019 20:57:50 GMT</pubDate>
    <dc:creator>Prakash493</dc:creator>
    <dc:date>2019-05-08T20:57:50Z</dc:date>
    <item>
      <title>splunk DB connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-DB-connect/m-p/449636#M171407</link>
      <description>&lt;P&gt;Hi Currently we have Splunk db connect installed on heavy forwarder and we have inputs configured on heavy forwarder version 3. Where we have outputs setup on search head that used some spl query to run. I want to use outputs setup on heavy forwarder but when i run those splu queries i am not getting any data , is their any way that i can make my heavy forwarder talk to my search heads to get the data or which is recommended to use outputs on heavy forwarder or in search heads ?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 20:57:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-DB-connect/m-p/449636#M171407</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-05-08T20:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: splunk DB connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-DB-connect/m-p/449637#M171408</link>
      <description>&lt;P&gt;The concept of "outputs" setup in SH is wrong and HF should NOT talk to Search Heads. &lt;/P&gt;

&lt;P&gt;The proper way to do for your case is&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Install DBconnect inputs in Heavy Forwarder&lt;/LI&gt;
&lt;LI&gt;Ensure the outputs.conf of Heavy Forwarder sends data to Indexers&lt;/LI&gt;
&lt;LI&gt;Ensure your SH reads from indexer. The data is shared from Indexer. So any SH should work afterwards. &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;In Summary , redirect all data from Heavy Forwarder to Indexer&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 21:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-DB-connect/m-p/449637#M171408</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-05-08T21:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: splunk DB connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-DB-connect/m-p/449638#M171409</link>
      <description>&lt;P&gt;Ok got it my inputs are on heavy forwarders whereas my outputs are on search head now if i move my outputs of db connect from search head to HF i am not getting any data your answer satisifies me to have outputs of db connector on search head so it will read data from indexers , dis i understand correct ?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 21:29:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-DB-connect/m-p/449638#M171409</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-05-08T21:29:28Z</dc:date>
    </item>
  </channel>
</rss>

