<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Merging data from a database into splunk in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Merging-data-from-a-database-into-splunk/m-p/103226#M7205</link>
    <description>&lt;P&gt;you might want to take a look at this app:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/apps/36664/splunk-mysql-connector"&gt;http://splunk-base.splunk.com/apps/36664/splunk-mysql-connector&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If the data in the database changes frequently, using a lookup is probably more efficient as you are not duplicating the data in Splunk.  If the data is more static and many more correlations or fields are required to join with other machine data, you could consider indexing the data from a file that you are already exporting.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2012 16:04:12 GMT</pubDate>
    <dc:creator>emotz</dc:creator>
    <dc:date>2012-07-19T16:04:12Z</dc:date>
    <item>
      <title>Merging data from a database into splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Merging-data-from-a-database-into-splunk/m-p/103225#M7204</link>
      <description>&lt;P&gt;With splunk, I would like to correlate event-driven data with data from a database. I am able to export from a database, say Mongo, to JSON and then import that data into splunk (or MySQL to csv)&lt;/P&gt;

&lt;P&gt;What is the best approach to merging data into splunk? &lt;/P&gt;

&lt;P&gt;The first approach I have in mind is to just import the full database (and possibly delete older uploads via | delete) to run reports on, but ideally, I would like to try merge data in.&lt;/P&gt;

&lt;P&gt;Any other approaches to this that comes to mind?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2012 14:48:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Merging-data-from-a-database-into-splunk/m-p/103225#M7204</guid>
      <dc:creator>brettcave</dc:creator>
      <dc:date>2012-07-19T14:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Merging data from a database into splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Merging-data-from-a-database-into-splunk/m-p/103226#M7205</link>
      <description>&lt;P&gt;you might want to take a look at this app:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/apps/36664/splunk-mysql-connector"&gt;http://splunk-base.splunk.com/apps/36664/splunk-mysql-connector&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If the data in the database changes frequently, using a lookup is probably more efficient as you are not duplicating the data in Splunk.  If the data is more static and many more correlations or fields are required to join with other machine data, you could consider indexing the data from a file that you are already exporting.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2012 16:04:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Merging-data-from-a-database-into-splunk/m-p/103226#M7205</guid>
      <dc:creator>emotz</dc:creator>
      <dc:date>2012-07-19T16:04:12Z</dc:date>
    </item>
  </channel>
</rss>

