All Apps and Add-ons

how can we configure multiple servers for a single index on Splunk

deeptha1992
New Member

I need to get data from more than 100 servers. every servers are standalone (there is no topology like one master and others are client.) I have created one connection with splunk DB connect app. But that will give data only from that connected server. How I can connect these every 100 + servers into one index?

0 Karma

deeptha1992
New Member

Thank you for your answers..

0 Karma

vishaltaneja070
Motivator

If it is really required, then you can do it with the help of configuration file as well. Which i think will be easy for you.

create new connection using db_connections.conf and identities.conf.

0 Karma

DMohn
Motivator

As tedious as this may sound - add DB connections for the other 100+ servers as well...

If you really need to run the same query on several dozens of (unconnected) DB servers, this might be the only reasonable solution. As long as we don't know which type of DB you are querying we can't tell if there might be some other, easier (non-splunk?) solution for this. But generally, you have to have one input per DB you are getting data from.

Maybe you don't have to set up each and every connection via the DBconnect UI, bur you can edit the config files directly, which - depending on the editor you are using - might be faster.

Please, keep one thing in mind when setting this up: DBConnect isn't the "cheapest" way of getting data into Splunk, from a system performance standpoint. So you might consider setting the query intervals in such a way that it spreads the load over some time, don't trigger all queries at once!

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...