<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is Splunk Hadoop Connect app supported in a clustered Search head? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343151#M41454</link>
    <description>&lt;P&gt;Hi BUrch,&lt;/P&gt;

&lt;P&gt;The goal is to move the data from Splunk to Hadoop/S3 for longer data retention. Currently we store data in Splunk only for two months.&lt;BR /&gt;
We want to send data to Hadoop and the analytics team wants to further analyse this HIVE , etc&lt;BR /&gt;
I understand&lt;BR /&gt;
 1) We can simply forward data to another system as it arrives at Splunk &lt;BR /&gt;
or&lt;BR /&gt;
2)  we can export data after it has been cooked by Splunk.&lt;BR /&gt;
 However not sure how to achieve first part.&lt;BR /&gt;
Hadoop connect allows data export to Hadoop but it doesnt seem to be supported in a clustered architecture. Thus looking out for options.&lt;/P&gt;

&lt;P&gt;I believe Hadoop Data Roll is used when I want to use Splunk again for archived data analytics, which is not needed for us. This archived index will follow the same two month retention period right? -- Please correct me if Im wrong.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Sep 2017 12:20:41 GMT</pubDate>
    <dc:creator>saranya_fmr</dc:creator>
    <dc:date>2017-09-22T12:20:41Z</dc:date>
    <item>
      <title>Is Splunk Hadoop Connect app supported in a clustered Search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343149#M41452</link>
      <description>&lt;P&gt;Goal is to set export Data from Splunk Indexes to Hadoop.&lt;/P&gt;

&lt;P&gt;We have a clustered Search head cluster. The doc doesn't mention about deploying the Splunk Hadoop Connector app in a cluster.&lt;/P&gt;

&lt;P&gt;The below page says its not supported in a clustered SH.&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/368847/is-hadoop-connect-supported-in-a-splunk-search-hea.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev"&gt;https://answers.splunk.com/answers/368847/is-hadoop-connect-supported-in-a-splunk-search-hea.html?utm_source=typeahead&amp;amp;utm_medium=newquestion&amp;amp;utm_campaign=no_votes_sort_relev&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So my Question is:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Is it supported in a Search Head Cluster? If no , what are the other options to send Splunk Index data into Hadoop ?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 20 Sep 2017 10:19:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343149#M41452</guid>
      <dc:creator>saranya_fmr</dc:creator>
      <dc:date>2017-09-20T10:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: Is Splunk Hadoop Connect app supported in a clustered Search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343150#M41453</link>
      <description>&lt;P&gt;If you want to get data export to indexers, how about &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Indexer/ArchivingindexestoHadoop"&gt;Hadoop Data Roll&lt;/A&gt;?&lt;/P&gt;

&lt;P&gt;Brief answer cause I wasn't positive why and the specifics about getting the data to Hadoop. Knowing more about that would help provide alternative solutions for this. Cool?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 19:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343150#M41453</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-09-20T19:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Is Splunk Hadoop Connect app supported in a clustered Search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343151#M41454</link>
      <description>&lt;P&gt;Hi BUrch,&lt;/P&gt;

&lt;P&gt;The goal is to move the data from Splunk to Hadoop/S3 for longer data retention. Currently we store data in Splunk only for two months.&lt;BR /&gt;
We want to send data to Hadoop and the analytics team wants to further analyse this HIVE , etc&lt;BR /&gt;
I understand&lt;BR /&gt;
 1) We can simply forward data to another system as it arrives at Splunk &lt;BR /&gt;
or&lt;BR /&gt;
2)  we can export data after it has been cooked by Splunk.&lt;BR /&gt;
 However not sure how to achieve first part.&lt;BR /&gt;
Hadoop connect allows data export to Hadoop but it doesnt seem to be supported in a clustered architecture. Thus looking out for options.&lt;/P&gt;

&lt;P&gt;I believe Hadoop Data Roll is used when I want to use Splunk again for archived data analytics, which is not needed for us. This archived index will follow the same two month retention period right? -- Please correct me if Im wrong.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 12:20:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343151#M41454</guid>
      <dc:creator>saranya_fmr</dc:creator>
      <dc:date>2017-09-22T12:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Is Splunk Hadoop Connect app supported in a clustered Search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343152#M41455</link>
      <description>&lt;P&gt;Thanks for the extra detail. It sounds like Hadoop Data Roll is exactly what you want. It's the ideal way to roll data from Splunk to Hadoop. Yes it will allow you to search it still but you don't have to do that AND it will have DIFFERENT retention than the index did in Splunk. Read through the documentation and I'm confident you'll agree that it's 100% exactly what you want to use.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 12:34:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343152#M41455</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-09-22T12:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is Splunk Hadoop Connect app supported in a clustered Search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343153#M41456</link>
      <description>&lt;P&gt;Thakyou for the notes. I will go through the documentation and get back incase of further queries.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 13:51:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343153#M41456</guid>
      <dc:creator>saranya_fmr</dc:creator>
      <dc:date>2017-09-22T13:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is Splunk Hadoop Connect app supported in a clustered Search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343154#M41457</link>
      <description>&lt;P&gt;Hi @SloshBurch ,&lt;/P&gt;

&lt;P&gt;I did go through the documentation and had few queries - I have posted these queries at the below link as well:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/577310/difference-between-data-format-for-the-data-sent-t.html?minQuestionBodyLength=80"&gt;https://answers.splunk.com/answers/577310/difference-between-data-format-for-the-data-sent-t.html?minQuestionBodyLength=80&lt;/A&gt;&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Firstly what is the difference between the data format of data that is sent via Hadoop Connect Export and Hadoop Data Roll?
I believe Hadoop Connect exports search results and Hadoop Data Roll send the raw data journal.gz&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Can I use Hadoop Techniques like Hive, Pig..etc for analytics  on the archived data sent to Hadoop via &lt;STRONG&gt;Hadoop Data Roll&lt;/STRONG&gt;?&lt;BR /&gt;
AND&lt;BR /&gt;
Can I use Hadoop Techniques like Hive, Pig..etc for analytics  on the archived data sent to Hadoop via &lt;STRONG&gt;Splunk Hadoop Connect Export&lt;/STRONG&gt;?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I came across Splunk Archive Bucket Reader - an additional app is required to analyze the archived data via Hadoop's applications like Pig , Hive , Spark.&lt;BR /&gt;
Is this a mandatory app required If I want to analyse the Hadoop  data?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Is &lt;STRONG&gt;Splunk Analytics for Hadoop license&lt;/STRONG&gt; license required for sending archived data to Hadoop?&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 26 Sep 2017 11:16:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343154#M41457</guid>
      <dc:creator>saranya_fmr</dc:creator>
      <dc:date>2017-09-26T11:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: Is Splunk Hadoop Connect app supported in a clustered Search head?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343155#M41458</link>
      <description>&lt;P&gt;Thanks @saranya_fmr. I was at .conf2017 and then another work trip hence the delayed response. I will respond in the new thread you created. Thanks for starting that.&lt;/P&gt;

&lt;P&gt;Also, if we answered your initial question, please make sure to accept that answer so others know if its worth exploring this thread or not.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 21:45:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-Splunk-Hadoop-Connect-app-supported-in-a-clustered-Search/m-p/343155#M41458</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-10-06T21:45:12Z</dc:date>
    </item>
  </channel>
</rss>

