Dashboards & Visualizations

KV Store share among 2 SearchHeads and a Heavy fowarder

myfriendhenry
Explorer

I have DB_Connect running only on the Heavy Forwarder. (Got that working)
I want to get a single value from a database (A Date Value), store it in the KV-Store on the Heavy Forwarder (I know how to do that)
I want that Key/Value to be available to both of my (non-clustered) Search Heads. - HOW TO DO THIS?

To clarify a bit. I want to put this value in a dashboard and don't want the query run directly from it.

1. I don't want search heads accessing the database
2. This should also yield somewhat better dashboard performance.

Would like the process to be something like this:
Scheduled DBXQuery Updates K/Value on HF | HF Replicates K/Value to Search Heads | Dashboard Queries K/Value

Tags (1)
0 Karma
1 Solution

starcher
Influencer

https://splunkbase.splunk.com/app/3519/

Use that as an alert action on the the HF. Send to a kvstore on the SH.
Your search would simply be an inputlookup of the HF local lookup table with the alert action attached.

View solution in original post

0 Karma

starcher
Influencer

https://splunkbase.splunk.com/app/3519/

Use that as an alert action on the the HF. Send to a kvstore on the SH.
Your search would simply be an inputlookup of the HF local lookup table with the alert action attached.

0 Karma

myfriendhenry
Explorer

Awesome, this appears to be the missing link.

0 Karma

myfriendhenry
Explorer

100% working, thank you!

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...