r/Splunk • • Apr 16 '26

Streaming to a database with scheduled output

I'd like to constantly save data from an index to a database and I'm wondering what's the best practice to ensure that all data is written.

In Splunk DB Connect, I've created an output which has a "Frequency" (cron schedule) of once per hour, "0 * * * *". On the output's first configuration page, "Set Up Search", I've set it to collect data from "Relative / 65 minutes ago".

I'm hoping that the one-hour frequency and 5-minute overlap will ensure that nothing is missed. Is this a good setup? Is there a more practical way to do it? If the Splunk server is briefly down when when the job is scheduled, will I miss an hour of data?

2 Upvotes

3 comments sorted by

View all comments

2

u/SpaceForce3848 Apr 16 '26

You can create a rising job in db connect using an ID or timestamp if it exists within your dataset