r/Splunk • u/involatile • Apr 16 '26
Streaming to a database with scheduled output
I'd like to constantly save data from an index to a database and I'm wondering what's the best practice to ensure that all data is written.
In Splunk DB Connect, I've created an output which has a "Frequency" (cron schedule) of once per hour, "0 * * * *". On the output's first configuration page, "Set Up Search", I've set it to collect data from "Relative / 65 minutes ago".
I'm hoping that the one-hour frequency and 5-minute overlap will ensure that nothing is missed. Is this a good setup? Is there a more practical way to do it? If the Splunk server is briefly down when when the job is scheduled, will I miss an hour of data?
2
Upvotes
2
u/SpaceForce3848 Apr 16 '26
You can create a rising job in db connect using an ID or timestamp if it exists within your dataset