All Apps and Add-ons

Splunk DB Connect: If using Output connection to insert in database, how is the Heavy Forwarder supposed to search my events in the index layer?

ahmedhassanean
Explorer

Dears,

i would like to install Splunk DB connect v3 but i have questions regarding recommended setup of it in a Heavy Forwarder. In case i am using Output connection to insert in database, how is the Heavy forwarder supposed to be able to search my events in the index layer?

thanks in advance

0 Karma
1 Solution

woodcock
Esteemed Legend

You will have to make your Heavy Forwarder a full Search Head by adding your Indexers as Search Peers (or migrate this function to your Search Head).

View solution in original post

0 Karma

woodcock
Esteemed Legend

You will have to make your Heavy Forwarder a full Search Head by adding your Indexers as Search Peers (or migrate this function to your Search Head).

0 Karma

ahmedhassanean
Explorer

agree with you but my questions is Guide already informed us to not add DB connect on SH cluster
So why they going for that they adding now extra processing to HF

0 Karma

woodcock
Esteemed Legend

These roles are just names. Make your HF a Search Head, too. Just use the GUI to add the Search Peers and that's it. It is just a name, for the most part. Do not add this stand-alone Search Head to the other SHC and DO NOT let other people login to it to run searches here.

0 Karma

eddiet
Explorer

Thanks for pointing this out.
Should really be documented. This and HEC dependency

0 Karma

woodcock
Esteemed Legend

The Heavy Forwarder is to run the DB Connect queries and then send (outputs.conf pointing to your Indexer tier) to your Indexers. The Heavy Forwarder does not "search your events" at all; it GENERATES them and stores them on the Indexers.

0 Karma

ahmedhassanean
Explorer

you are talking about Input connection which mean run query into database and send data to indexers
but i am talking about inserting data from splunk to Database through Output connection in DB connect it self
how supposed DB connect will search my events that exist in indexer tier

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...