Deployment Architecture

How can I have the auto db-lookups in distributed environment?

luhadia_aditya
Path Finder

I am aware that the auto-lookup functionality is not supported with db-lookups, due to constrain of running the db-lookup locally only on the search head.

Example - index=test | lookup local=1 mysql_table ip_address as clientip OUTPUT host | table clientip, host

Which is not achievable with auto-lookup.

Is there any work-around to this ?
Can I install db-connect app on the indexers as well and have the streaming db-lookup running on both the instances, indexers + search head ?

Using distributed environment (1 HFWD, 2 IDX, 1 SH), on Splunk 6.0.4 (build 207768), dbx 1.1.6. Any help is appreciated! Thanks!

dounla2carlos
Explorer

hi i'm try to solve this probleme

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...