Deployment Architecture

Is there a way to propagate dbquery result to all search heads?

joeldavideng
Path Finder

I am running a daily query against an external database that provides a list of assets that many of my searches utilize. The searches exist on multiple search heads and I would like to avoid having to install DB Connect on all of them and replicate the expensive search. Is there a way to have the query run once on a centralized node and then have the others pull this list on a daily basis without having to use the deployment server?

0 Karma
1 Solution

starcher
Influencer

Run DBX on a heavy forwarder. Have your query send to a kvstore lookup on the target SHs or SHC using the alert action in: https://splunkbase.splunk.com/app/3519/

View solution in original post

starcher
Influencer

Run DBX on a heavy forwarder. Have your query send to a kvstore lookup on the target SHs or SHC using the alert action in: https://splunkbase.splunk.com/app/3519/

joeldavideng
Path Finder

This app is fire. Thanks a lot!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...