All Apps and Add-ons

Use DBConnect/dbxquery to Populate a Lookup Table having more than a Million Rows

mnm1987
Explorer

Hello Splunkers,
What is the best possible approach to use inorder to build a Lookup table in Splunk which would have more than a Million Rows, the source of which is a Database Table.

I have tried using DbConnect to fetch the data and Index it into Splunk, but to make it usable we end up needing to run a subsearch for all time and also dedup the results. The issue with the above is that 1) Its Slow 2) Sub-Search Needs to run on all time.

Thanks.

0 Karma

woodcock
Esteemed Legend

You could build another system that access the DB and publishes the list on a webserver and use this app:

https://splunkbase.splunk.com/app/635/

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Is this maybe what you are looking for?

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...