Agreed - forcing the use of DB Input has two side effects:
1) Ingesting the entire dataset into a Splunk index from the source DB - data duplication, synchronization issues, ETL is bad when datasets are large (think Phoenix on HBase!)
2) DB Input counts towards ones Splunk quotas - Sorry that's double dipping...
... View more