Splunk® DB Connect

Deploy and Use Splunk DB Connect

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® DB Connect. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Install and configure Splunk DB Connect on a Splunk Cloud

Deploy DB Connect to Splunk Cloud Victoria Experience

If you want to deploy DB Connect to Victoria Experience, please see Install an add-on in Splunk Cloud for details. DB Connect on Victoria Experience must be deployed only on Search Head instances. Search Head instances on Victoria Experience will already have a supported version of JRE installed. If you install DB connect on a single instance then on search head will be offered full functionality. If DB Connect is installed on search head cluster environment please consider limitation for setting up DB connect on distributed environment describer in Performance considerations in distributed environments. Start the DB Connect installation process:

  1. Outbound ports are closed by default on Victoria Experience. Splunk Cloud Platform provides the Admin Config Service (ACS) API which you can use to open ports to allow outbound network connections to specific IP subnets programmatically. For details on how to use the ACS API see ACS API Documentation
  2. Follow the instructions to install DB Connect on a Search Head
  3. Install a JDBC driver add-on for your database. See new drivers using JDBC Driver addonsJDBC driver add-ons JDBC driver add-ons. If an add-on is not available for your database, or you require a different version of the driver than provided by the add-on please contact Splunk Support for help.
  4. After installing DB Connect and restarting Splunk, launch DB Connect.
  5. Create a database identity and set up a database connection.
  6. Create a new database input and use it as a data input in a Splunk search.

Migrate DB connect from Splunk Enterprise to Splunk Cloud Victoria Experience

DB Connect has differences in managing it on Splunk Cloud Victoria Experience. Below list prest those differences:

  • Installing JDBC drivers other than served by JDBC Add-ons is not possible on Splunk Cloud Victorian Experience. In case of necessity of having other drivers idea need to be create on Idea Portal
  • Migrate from Single Instance of Splunk Enterprise to Search Head Cluster environment in Victoria Experience consider limitation described in Performance considerations in distributed environments. To workaround Search Head Cluster limitation please consider setting up Heavy Forwarder with DB Connect.
  • Outbound ports on Splunk Cloud Victoria Experience are closed by default. It may prevent connecting to your database from Search Head with DB Connect installed. Please follow the instructions to open the Outbound port from Search Head to your Database. Splunk Cloud Platform provides the Admin Config Service (ACS) API which you can use to open ports to allow outbound network connections to specific IP subnets programmatically. For details on how to use the ACS API see ACS API Documentation.

Deploy DB Connect to Splunk Cloud Classic Experience

If you want to deploy DB Connect to Splunk Cloud, contact Splunk Support for guidance and assistance. You cannot deploy DB Connect yourself because you cannot configure network access to databases on your Splunk Cloud instance. See Install an add-on in Splunk Cloud for details.

Last modified on 09 February, 2022
PREVIOUS
Install and configure Splunk DB Connect on a distributed Splunk platform deployment
  NEXT
Check DB Connect installation health

This documentation applies to the following versions of Splunk® DB Connect: 3.8.0, 3.9.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters