All Apps and Add-ons

how can we configure multiple servers for a single index on Splunk

deeptha1992
New Member

I need to get data from more than 100 servers. every servers are standalone (there is no topology like one master and others are client.) I have created one connection with splunk DB connect app. But that will give data only from that connected server. How I can connect these every 100 + servers into one index?

0 Karma

deeptha1992
New Member

Thank you for your answers..

0 Karma

vishaltaneja070
Motivator

If it is really required, then you can do it with the help of configuration file as well. Which i think will be easy for you.

create new connection using db_connections.conf and identities.conf.

0 Karma

DMohn
Motivator

As tedious as this may sound - add DB connections for the other 100+ servers as well...

If you really need to run the same query on several dozens of (unconnected) DB servers, this might be the only reasonable solution. As long as we don't know which type of DB you are querying we can't tell if there might be some other, easier (non-splunk?) solution for this. But generally, you have to have one input per DB you are getting data from.

Maybe you don't have to set up each and every connection via the DBconnect UI, bur you can edit the config files directly, which - depending on the editor you are using - might be faster.

Please, keep one thing in mind when setting this up: DBConnect isn't the "cheapest" way of getting data into Splunk, from a system performance standpoint. So you might consider setting the query intervals in such a way that it spreads the load over some time, don't trigger all queries at once!

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...