<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk DB Connect Charges in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Charges/m-p/704509#M20825</link>
    <description>Hi&lt;BR /&gt;I think that it's doable.&lt;BR /&gt;Splunk count only indexed data on indexers not from HF. I suppose that you are running DBX on separate HF and then it goes only into Cribl and Cribl send it to indexers? If that is valid assumption then you pay only that amount of data what indexers are indexing.&lt;BR /&gt;r. Ismo</description>
    <pubDate>Fri, 15 Nov 2024 14:11:36 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2024-11-15T14:11:36Z</dc:date>
    <item>
      <title>Splunk DB Connect Charges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Charges/m-p/704486#M20823</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm new to Splunk DB connector. Having Splunk on-prem version and trying to pull data from Snowflake audit logs and push to cribl.io (for log optimization purpose and reducing log size).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As Cribl.io&amp;nbsp;&lt;STRONG&gt;doesn't&lt;/STRONG&gt; have connector for Snowflake (and not in near roadmap), wondering if I use Splunk DB connect to read data from Snowflake and send to Cribl.io followed by sending to destination i.e. Splunk (for log monitoring and alerting)&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt; &lt;/FONT&gt;&lt;FONT color="#FF0000"&gt;Would this be "double hop" to Splunk, if yes, any Splunk charges be applicable while Splunk DB connect reading from Snowflake and sending to Cribl.io?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;Avi&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 08:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Charges/m-p/704486#M20823</guid>
      <dc:creator>avifyi</dc:creator>
      <dc:date>2024-11-15T08:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect Charges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Charges/m-p/704509#M20825</link>
      <description>Hi&lt;BR /&gt;I think that it's doable.&lt;BR /&gt;Splunk count only indexed data on indexers not from HF. I suppose that you are running DBX on separate HF and then it goes only into Cribl and Cribl send it to indexers? If that is valid assumption then you pay only that amount of data what indexers are indexing.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Fri, 15 Nov 2024 14:11:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Charges/m-p/704509#M20825</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-11-15T14:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect Charges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Charges/m-p/704650#M20846</link>
      <description>&lt;P&gt;Hi, yes I've tested this use case in env and things are working as expected. I was more concerned about hidden charges when we start blowing things. Thanks for making this straight for me. It's helpful.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 15:49:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Charges/m-p/704650#M20846</guid>
      <dc:creator>avifyi</dc:creator>
      <dc:date>2024-11-18T15:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect Charges</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Charges/m-p/704693#M20849</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274060"&gt;@avifyi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good day to you. thanks for the interesting question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt;&amp;gt;&amp;gt;cribl.io (for log optimization purpose and reducing log size)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;1) May we know some details about how much data (approx) you are having the plan?&lt;/P&gt;&lt;P&gt;-------from Splunk DB Connector to cribl.io&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) may we know, approximately how much optimization and log size reduction you planning to achieve using the cribl.io?&lt;BR /&gt;3) though its doable task, it may not be necessary at all at sometimes &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;4) from where the Splunk DB Connector is reading the logs? lets say you have a DB X.&amp;nbsp;&lt;BR /&gt;X DB ----- &amp;gt; Splunk DB Connector ----- &amp;gt; Cribl.io ------ &amp;gt; back to Splunk&lt;/P&gt;&lt;P&gt;instead of this, maybe plan about&lt;/P&gt;&lt;P&gt;X DB ------&amp;gt; cribl.io-------&amp;gt; to Splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Best Regards&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(PS - my karma stats - given 2000+ and received 500. thanks for reading )&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 04:40:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Charges/m-p/704693#M20849</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-11-19T04:40:06Z</dc:date>
    </item>
  </channel>
</rss>

