Getting Data In

Splunk DB Connect: is this possible to add/update data to DB from Search-Head (in SH cluster Env)

pargupta1234
New Member

I am planning to use DB-connect in my workflow. Right now all our lookups lie on SH nodes. 

I want to add/update processed data to DB from SH nodes (in a clustered env) . Is this possible to do so using dbxoutput command ?

NOTE :processed data is created  from some intermediate lookups which lie on SH nodes

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @pargupta1234,

yes it's possible using DB-Connect and giving the correct grants to the user.: you can run all the queries you want, also add/update quesries.

But put very much attention to this because it isn't a security best practice!

I usually avoid to give add/update grants to Splunk users.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...