<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get logs from snowflake into Splunk in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-get-logs-from-snowflake-into-Splunk/m-p/678545#M2853</link>
    <description>&lt;P&gt;I found this -&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.snowflake.com/s/article/Integrating-Snowflake-and-Splunk-with-DBConnect" target="_blank"&gt;https://community.snowflake.com/s/article/Integrating-Snowflake-and-Splunk-with-DBConnect&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It looks like it walks you through exactly how to do that.&lt;/P&gt;&lt;P&gt;If that helps, karma's always appreciated!&lt;/P&gt;&lt;P&gt;Happy Splunking Snowflake data!&lt;/P&gt;&lt;P&gt;-Rich&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2024 21:44:04 GMT</pubDate>
    <dc:creator>Richfez</dc:creator>
    <dc:date>2024-02-23T21:44:04Z</dc:date>
    <item>
      <title>How to get logs from snowflake into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-get-logs-from-snowflake-into-Splunk/m-p/678482#M2852</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have requirement to get logs into Splunk from Snowflake. I have no idea where to start from.&lt;/P&gt;&lt;P&gt;I came across Splunk docs using Splunk DB connect.&lt;A href="https://docs.splunk.com/Documentation/DBX/3.15.0/DeployDBX/Installdatabasedrivers" target="_blank"&gt;https://docs.splunk.com/Documentation/DBX/3.15.0/DeployDBX/Installdatabasedrivers&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can you'll guide me how do i get started here? How do I get logs from Snowflake into Splunk. Can I use HEC token to- get the logs?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 13:12:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-get-logs-from-snowflake-into-Splunk/m-p/678482#M2852</guid>
      <dc:creator>Splunkerninja</dc:creator>
      <dc:date>2024-02-23T13:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to get logs from snowflake into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-get-logs-from-snowflake-into-Splunk/m-p/678545#M2853</link>
      <description>&lt;P&gt;I found this -&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.snowflake.com/s/article/Integrating-Snowflake-and-Splunk-with-DBConnect" target="_blank"&gt;https://community.snowflake.com/s/article/Integrating-Snowflake-and-Splunk-with-DBConnect&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It looks like it walks you through exactly how to do that.&lt;/P&gt;&lt;P&gt;If that helps, karma's always appreciated!&lt;/P&gt;&lt;P&gt;Happy Splunking Snowflake data!&lt;/P&gt;&lt;P&gt;-Rich&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 21:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-get-logs-from-snowflake-into-Splunk/m-p/678545#M2853</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2024-02-23T21:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to get logs from snowflake into Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-get-logs-from-snowflake-into-Splunk/m-p/705876#M3405</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/205010"&gt;@Richfez&lt;/a&gt;&amp;nbsp;or&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262258"&gt;@Splunkerninja&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;I've successfully ingested the Snowflake LOGIN_HISTORY and SESSIONS tables but I'm running into roadblock after roadblock with the ACCESS_HISTORY and QUERY_HISTORY table ingestions.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.snowflake.com/en/sql-reference/account-usage/access_history" target="_blank"&gt;https://docs.snowflake.com/en/sql-reference/account-usage/access_history&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.snowflake.com/en/sql-reference/account-usage/query_history" target="_blank"&gt;https://docs.snowflake.com/en/sql-reference/account-usage/query_history&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;These tables have a QUERY_ID field that looks like this:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;a0fda135-d678-4184-942b-c3411ae8d1ce&lt;/P&gt;&lt;P&gt;And a QUERY_START_TIME (TIMESTAMP_LTZ) field that looks like this:&lt;BR /&gt;&lt;SPAN class=""&gt;2022-01-25&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;16:17:47.388&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;+0000&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;The Checkpoint value system for a Rising ingestion in the Splunk DB Connect app doesn't play nicely with either of these fields and I've tried creating temporary fields and tables to bypass this issues but not to avail.&lt;/P&gt;&lt;P&gt;For the QUERY_ID, I tried removing the hyphens and replace the letters a,b,c,d,e,f with numeric values 1,2,3,4,5,6 and stored it in a different field called QUERY_ID_NUMERIC. When trying that out as the checkpoint value, the checkpoint never gets updated so it just ingests the same data over and over again.&lt;BR /&gt;&lt;BR /&gt;Similarly for the QUERY_START_TIME, I've tried casting the&amp;nbsp;TIMESTAMP_LTZ to&amp;nbsp;TIMESTAMP_NTZ and saved that as a new field QUERY_START_TIME_NTZ and that ingests the data but the checkpoint value isn't updating either.&lt;BR /&gt;&lt;BR /&gt;I was wondering if anyone has experienced this issue when ingesting these two data sources and if they've found any work arounds that resolved it!&lt;BR /&gt;&lt;BR /&gt;Thank you very much!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2024 19:14:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-get-logs-from-snowflake-into-Splunk/m-p/705876#M3405</guid>
      <dc:creator>trobknight7</dc:creator>
      <dc:date>2024-12-03T19:14:04Z</dc:date>
    </item>
  </channel>
</rss>

