All Apps and Add-ons

How to perform a query on the HF that will allow me to then send the data I return to a DB?

dfurtaw
Path Finder

Hi Splunk Answer guys/gals,

I have a question regarding DBConnect and I was curious if anyone had any insight on it. After reading the documentation, I'm still a bit unsure on how to use the DB Output feature that is included in dbconnect. I have dbconnect installed on one of our HF's but in order for the output command to work, I'll need to search the data that is in our Splunk Cloud instance. 

The HF is currently configured to send data to the indexers, but I'm stuck on figuring out how I'll be able to perform a query on the HF that will allow me to then send the data I return to a DB. Currently, I'm unable to pull any data on the HF.

Thank you!

DFurtaw

Labels (1)
0 Karma
1 Solution

chli_splunk
Splunk Employee
Splunk Employee

Unlike DBX input, DBX output is a custom search command to export data from Splunk search results to DB. So it has to run on search head rather than HF. In your case, I'm afraid you have to install DBX on search head, configure it and run DBX output like a search command.

View solution in original post

chli_splunk
Splunk Employee
Splunk Employee

Unlike DBX input, DBX output is a custom search command to export data from Splunk search results to DB. So it has to run on search head rather than HF. In your case, I'm afraid you have to install DBX on search head, configure it and run DBX output like a search command.

richgalloway
SplunkTrust
SplunkTrust
For Splunk Cloud, you need to configure Hybrid Search so your local search head (which can be the HF) can fetch data from Cloud indexers.
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...