Deployment Architecture

Is there a way to propagate dbquery result to all search heads?

joeldavideng
Path Finder

I am running a daily query against an external database that provides a list of assets that many of my searches utilize. The searches exist on multiple search heads and I would like to avoid having to install DB Connect on all of them and replicate the expensive search. Is there a way to have the query run once on a centralized node and then have the others pull this list on a daily basis without having to use the deployment server?

0 Karma
1 Solution

starcher
Influencer

Run DBX on a heavy forwarder. Have your query send to a kvstore lookup on the target SHs or SHC using the alert action in: https://splunkbase.splunk.com/app/3519/

View solution in original post

starcher
Influencer

Run DBX on a heavy forwarder. Have your query send to a kvstore lookup on the target SHs or SHC using the alert action in: https://splunkbase.splunk.com/app/3519/

joeldavideng
Path Finder

This app is fire. Thanks a lot!

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...