<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk MySQL Connector  -&amp;gt; Can do this? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-MySQL-Connector-gt-Can-do-this/m-p/68453#M70592</link>
    <description>&lt;P&gt;I have a table of ~11 million rows and 53 columns. The table looks like:&lt;/P&gt;

&lt;P&gt;entity_id | week_1 | week_2 | ..... | week_52&lt;BR /&gt;
abcd      | 35874  | 587489 |.......| 5478&lt;/P&gt;

&lt;P&gt;While we discover new entities with splunk the table can grow up to ~30 million rows.&lt;/P&gt;

&lt;P&gt;I was wondering the following:&lt;BR /&gt;
-. What is the maximum number of lookup output fields that MySQL connector can support? &lt;BR /&gt;
-. Can I have up to 52 or 365 look up output fields?&lt;BR /&gt;
-. what is the recommended maximum number of rows a lookup table can have?&lt;BR /&gt;
-. If new entities and weekly data are discovered can Splunk MySQL connector insert the new entities and weekly data in the lookup table that is stored in MySQL?&lt;BR /&gt;
-. In case we need to update, delete or insert some weekly data can Splunk MySQL connector perform updates, delete, and insert of this magnitude?&lt;BR /&gt;
-. Is there any other approach you might recommend?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Lp&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 11:22:11 GMT</pubDate>
    <dc:creator>lpolo</dc:creator>
    <dc:date>2020-09-28T11:22:11Z</dc:date>
    <item>
      <title>Splunk MySQL Connector  -&gt; Can do this?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-MySQL-Connector-gt-Can-do-this/m-p/68453#M70592</link>
      <description>&lt;P&gt;I have a table of ~11 million rows and 53 columns. The table looks like:&lt;/P&gt;

&lt;P&gt;entity_id | week_1 | week_2 | ..... | week_52&lt;BR /&gt;
abcd      | 35874  | 587489 |.......| 5478&lt;/P&gt;

&lt;P&gt;While we discover new entities with splunk the table can grow up to ~30 million rows.&lt;/P&gt;

&lt;P&gt;I was wondering the following:&lt;BR /&gt;
-. What is the maximum number of lookup output fields that MySQL connector can support? &lt;BR /&gt;
-. Can I have up to 52 or 365 look up output fields?&lt;BR /&gt;
-. what is the recommended maximum number of rows a lookup table can have?&lt;BR /&gt;
-. If new entities and weekly data are discovered can Splunk MySQL connector insert the new entities and weekly data in the lookup table that is stored in MySQL?&lt;BR /&gt;
-. In case we need to update, delete or insert some weekly data can Splunk MySQL connector perform updates, delete, and insert of this magnitude?&lt;BR /&gt;
-. Is there any other approach you might recommend?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Lp&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:22:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-MySQL-Connector-gt-Can-do-this/m-p/68453#M70592</guid>
      <dc:creator>lpolo</dc:creator>
      <dc:date>2020-09-28T11:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk MySQL Connector  -&gt; Can do this?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-MySQL-Connector-gt-Can-do-this/m-p/68454#M70593</link>
      <description>&lt;UL&gt;
&lt;LI&gt;What is the maximum number of lookup output fields that MySQLconnector can support? 
&lt;BR /&gt;&lt;FONT color="red"&gt; There is no inherent maximum number of output fields - if MySQL can support it so can the MySQL connector&lt;/FONT&gt; &lt;/LI&gt;
&lt;LI&gt;Can I have up to 52 or 365 look up output fields?
&lt;BR /&gt;&lt;FONT color="red"&gt;Yes, you should be able to&lt;/FONT&gt; &lt;/LI&gt;
&lt;LI&gt;what is the recommended maximum number of rows a lookup table can have? 
&lt;BR /&gt;&lt;FONT color="red"&gt;This depends in a lot of things such as the MySQL server spec, MySQL tuning, schema design etc. With a commodity server and some tuning you should be able to get decent performance with hundreds of millions of rows&lt;/FONT&gt; &lt;/LI&gt;
&lt;LI&gt;If new entities and weekly data are discovered can Splunk MySQL connector insert the new entities and weekly data in the lookup table that is stored in MySQL? 
&lt;BR /&gt;&lt;FONT color="red"&gt;Yes, you should be able to - look in mysqloutput command&lt;/FONT&gt; &lt;/LI&gt;
&lt;LI&gt;In case we need to update, delete or insert some weekly data can Splunk MySQL connector perform updates, delete, and insert of this magnitude?
&lt;BR /&gt;&lt;FONT color="red"&gt;Yes, you can use scheduled searches in Splunk to execute any table maintenance, look into mysqlquery command&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;Is there any other approach you might recommend?
&lt;BR /&gt;&lt;FONT color="red"&gt;As far as maintenance of the tables you can also use cron jobs to run maintenance scripts&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 09 Feb 2012 17:26:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-MySQL-Connector-gt-Can-do-this/m-p/68454#M70593</guid>
      <dc:creator>Ledion_Bitincka</dc:creator>
      <dc:date>2012-02-09T17:26:30Z</dc:date>
    </item>
  </channel>
</rss>

