Deployment Architecture

How can I have the auto db-lookups in distributed environment?

luhadia_aditya
Path Finder

I am aware that the auto-lookup functionality is not supported with db-lookups, due to constrain of running the db-lookup locally only on the search head.

Example - index=test | lookup local=1 mysql_table ip_address as clientip OUTPUT host | table clientip, host

Which is not achievable with auto-lookup.

Is there any work-around to this ?
Can I install db-connect app on the indexers as well and have the streaming db-lookup running on both the instances, indexers + search head ?

Using distributed environment (1 HFWD, 2 IDX, 1 SH), on Splunk 6.0.4 (build 207768), dbx 1.1.6. Any help is appreciated! Thanks!

dounla2carlos
Explorer

hi i'm try to solve this probleme

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...