Setting Up Remote Data Stores
Orbital will not send results that are over 250 MB to a remote data store.
Adding a Remote Data Store
You can define a new remote data store for your queries results. To add a new remote data store:
- Go to Administration > Remote Data Store.
- Click + Add remote data store.
- Select the destination: Default, Amazon S3, Azure, or Splunk.
- Fill in the required fields:
- Enter a unique name for the remote data store.
- Enter the URL (Container URL for Azure, HEC URL for Splunk) of the remote data store service.
- Optionally, enter the authentication token that you will obtain from the remote data store provider you are connecting to (not applicable for Amazon S3).
- Optionally, enter a fingerprint in SHA-256 format. For more information, see Obtaining a SHA-256 Fingerprint.
Select the Result format: Compact (the default one) or Expanded.
Required fields for Amazon S3:
Bucket
Region
Access key
Secret key
-
Click Save. The data store is added to the list. You can select it as a destination for results when scheduling a query.
You can also create a Remote Data Store directly from the Schedule or Run with remote data store drawer without navigating to Administration. After saving, you are returned to the original drawer and the Remote data store field is automatically filled in with the new data store.
Editing a Remote Data Store
To edit an existing remote data store:
- Go to Administration > Remote Data Store.
- Click the three-dot menu at the end of a row you want to edit and select Edit. The Edit remote data store drawer appears.
-
Modify the needed values.
-
Click Save. The modified data store information is saved to the data store definition.
Deleting a Remote Data Store
You can delete an existing remote data store if the service is unavailable or does not meet your needs:
- Go to Administration > Remote Data Store.
-
Click the three-dot menu at the end of a row you want to delete and select Delete. The Delete data store drawer appears.
-
Click Delete. It will remove the remote data store definition from Orbital and refresh the remote data store list.
Obtaining a SHA-256 Fingerprint
If the remote data store is self-signed, you need to obtain a SHA-256 fingerprint. Depending on the web browser that you use, the procedure for obtaining the fingerprint will differ.
You can obtain the necessary fingerprint using the command shown below.
| > openssl x509 -noout -fingerprint -sha256 -inform pem -in <filename>.crt |
For more details about certificates and fingerprint, contact your host administrator.