<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What underlying database Splunk uese to operate? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20305#M403</link>
    <description>&lt;P&gt;I understand indexing but that is not the only place or way the Splunk stores data.  &lt;/P&gt;</description>
    <pubDate>Thu, 16 Feb 2017 15:01:32 GMT</pubDate>
    <dc:creator>bspargur1</dc:creator>
    <dc:date>2017-02-16T15:01:32Z</dc:date>
    <item>
      <title>What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20297#M395</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;
      i am newbie in splunk, i searched over documentation and also over community. but i did not get answer for question in my mind. &lt;BR /&gt;
    Question is :- What database Splunk uses to work ? like Oracle or MySQL or PostgreSQL ? &lt;/P&gt;

&lt;P&gt;i also read one already posted question as provided on below link&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/32499/what-database-engine-splunk-uses"&gt;http://splunk-base.splunk.com/answers/32499/what-database-engine-splunk-uses&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;on same link, in answers it is written like below :-&lt;BR /&gt;
I am not sure what is unclear to you in the previous answer. Splunk uses it's own engine, and does not rely on any external databases in order to operate. It manages its own database via a series of flat files and indexes, and Damien has provided a few good resources for you to have an idea on how the data engine works.&lt;/P&gt;

&lt;P&gt;does it means Splunk do not use any database like Oracle or MySQL etc ?&lt;/P&gt;

&lt;P&gt;thanks &amp;amp; regards,&lt;BR /&gt;
Somnath&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2013 13:40:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20297#M395</guid>
      <dc:creator>SomnathShilimka</dc:creator>
      <dc:date>2013-04-30T13:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20298#M396</link>
      <description>&lt;P&gt;Indeed, no separate relational DB. The data structure underneath is Splunk-built.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2013 13:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20298#M396</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-04-30T13:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20299#M397</link>
      <description>&lt;P&gt;Hi Martin_mueller&lt;BR /&gt;
          thanks for reply, i know for splunk no need of separate DB, what i want to know is :- what is name of that Splunk-built database(data structure) ? &lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Somnath&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2013 14:45:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20299#M397</guid>
      <dc:creator>SomnathShilimka</dc:creator>
      <dc:date>2013-04-30T14:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20300#M398</link>
      <description>&lt;P&gt;There is no separate product underneath, it's been built by Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2013 14:48:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20300#M398</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-04-30T14:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20301#M399</link>
      <description>&lt;P&gt;There are the indexes which are flat files.  The lookups are csv files or mongodb.  The alerts require relationships and are also stored in a DB but I can't recall off hand if it is mysql or mongodb.  I think it is mysql.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 14:24:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20301#M399</guid>
      <dc:creator>bspargur1</dc:creator>
      <dc:date>2017-02-16T14:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20302#M400</link>
      <description>&lt;P&gt;nope, mysql is not used inside splunk .&lt;BR /&gt;
the kvstore is mongo, but again this is not used by splunk for anykind of relationship mapping or storage.\&lt;BR /&gt;
The kvstore is provided for splunk applications to use not for splunk per se.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 14:47:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20302#M400</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-02-16T14:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20303#M401</link>
      <description>&lt;P&gt;These links should clarify that:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Howindexingworks"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Howindexingworks&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.1/Indexer/HowSplunkstoresindexes"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.1/Indexer/HowSplunkstoresindexes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 14:52:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20303#M401</guid>
      <dc:creator>stanwin</dc:creator>
      <dc:date>2017-02-16T14:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20304#M402</link>
      <description>&lt;P&gt;You are looking specifically at the indexes.  The kvstores are the mongodb.  Do you have reference to how the Splunk generated alerts are stored?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 14:55:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20304#M402</guid>
      <dc:creator>bspargur1</dc:creator>
      <dc:date>2017-02-16T14:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20305#M403</link>
      <description>&lt;P&gt;I understand indexing but that is not the only place or way the Splunk stores data.  &lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 15:01:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20305#M403</guid>
      <dc:creator>bspargur1</dc:creator>
      <dc:date>2017-02-16T15:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20306#M404</link>
      <description>&lt;P&gt;When you configure alerts in Splunk, where are they stored?  How is the relationship to the event data that was used to generate the alert stored?  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Splunk uses the mongodb to store data becasue csv files suck as they start to get large.  I have always been curious why they used a json structured db over just using their flat file structure of the indexes with the mappings built in.  Maybe because it is good and already existed? &lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 15:12:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20306#M404</guid>
      <dc:creator>bspargur1</dc:creator>
      <dc:date>2017-02-16T15:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20307#M405</link>
      <description>&lt;P&gt;&lt;IMG src="https://ihasabucket.com/images/walrus_bucket.jpg" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 16:10:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20307#M405</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2017-02-16T16:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20308#M406</link>
      <description>&lt;P&gt;Haha, that was an awesome pic.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 16:17:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20308#M406</guid>
      <dc:creator>bspargur1</dc:creator>
      <dc:date>2017-02-16T16:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: What underlying database Splunk uese to operate?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20309#M407</link>
      <description>&lt;P&gt;Thats a biiiiig bucket &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2017 18:38:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-underlying-database-Splunk-uese-to-operate/m-p/20309#M407</guid>
      <dc:creator>stanwin</dc:creator>
      <dc:date>2017-02-16T18:38:08Z</dc:date>
    </item>
  </channel>
</rss>

