All Apps and Add-ons

Using Splunk DB Connect 2 in a search head cluster, should database inputs originally set on the deployer be set to disabled or enabled?

sim_tcr
Communicator

Hello,

We are using Splunk DB Connect 2 in a search head clustering environment.
Whenever we have to set up a new database input, we set up the input on the DBX2 app on the deployer (separate Splunk instance from search heads) and then do cp -rf /apps/splunk/etc/apps/splunk_app_db_connect /apps/splunk/etc/shcluster/apps
and run splunk apply shcluster-bundle -target https://nameofonesoftheearchheadclustermember:port. It gets pushed out to all search head cluster members, but the input actually runs on the captain only.

Question is, should the input we originally set on the deployer be set to disabled or left in an enabled state?

If we leave it enabled - won't the input run from two places and create issues?
If we leave it disabled - next time when there is a need to set up a new input, before pushing the new input to search heads, we have to enable all previous inputs, else all the previous inputs go to disabled state on search heads.

On a side note: Does any one have issues deleing an existing input created on the DB Connect 2 app from the GUI? I tried, but it simply wont go away, and I have deleted it from the inputs.conf.

Thanks,
Simon Mandy

stanwin
Contributor

So i think it can be enabled and deployed to all the members.

In a search head cluster, DB Connect is deployed to all cluster members, but only runs on the search head cluster captain.

http://docs.splunk.com/Documentation/DBX/2.4.0/DeployDBX/Distributeddeployment#Search_head_clusters

0 Karma

jayannah
Builder

You disable at App level instead of individual inputs.

If we leave it disabled - next time when there is a need to set up a new input, before pushing the new input to search heads, we have to enable all previous inputs, else all the previous inputs go to disabled state on search heads.

I was able to delete the inputs successfully.

does any one have issues deleing an existing input created on the DB Connect 2 app from the GUI?

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...