Splunk can certainly bulk load, and in fact DB Connect is designed for that, but similar to the tone of my earlier answer where I prefaced that using Splunk isn't the best solution to this problem... I agree that using Splunk isn't usually the best solution to this problem. The solutions you proposed are just as good if not better. However, the fact that @leo_y already has the data consolidated in Splunk makes it more compelling to use a database output from Splunk. If he has no other way to get the data, he'd need to export from Splunk to use your methods, which is suboptimal.
... View more