All Apps and Add-ons

Use DBConnect/dbxquery to Populate a Lookup Table having more than a Million Rows


Hello Splunkers,
What is the best possible approach to use inorder to build a Lookup table in Splunk which would have more than a Million Rows, the source of which is a Database Table.

I have tried using DbConnect to fetch the data and Index it into Splunk, but to make it usable we end up needing to run a subsearch for all time and also dedup the results. The issue with the above is that 1) Its Slow 2) Sub-Search Needs to run on all time.


0 Karma

Esteemed Legend

You could build another system that access the DB and publishes the list on a webserver and use this app:

0 Karma

Splunk Employee
Splunk Employee

Is this maybe what you are looking for?

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...