<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk as a general purpose data store? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-as-a-general-purpose-data-store/m-p/265625#M8337</link>
    <description>&lt;P&gt;Anyone?   .  &lt;/P&gt;</description>
    <pubDate>Thu, 08 Sep 2016 09:17:04 GMT</pubDate>
    <dc:creator>rogeralsing</dc:creator>
    <dc:date>2016-09-08T09:17:04Z</dc:date>
    <item>
      <title>Splunk as a general purpose data store?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-as-a-general-purpose-data-store/m-p/265624#M8336</link>
      <description>&lt;P&gt;Can, or rather should I use Splunk as a general purpose data store?&lt;/P&gt;

&lt;P&gt;We already use Splunk for logging and metrics and ingest about 100 gigs of data per day.&lt;/P&gt;

&lt;P&gt;But the question have been brought up, if we need to do general purpose free text searches or structural searches from our line of business applications.&lt;BR /&gt;
Is storing that data in Splunk a viable option?&lt;BR /&gt;
If so, even long term storage?&lt;/P&gt;

&lt;P&gt;Another usecase, if we do event sourcing (&lt;A href="http://www.martinfowler.com/eaaDev/EventSourcing.html?s_tact=C43202QW"&gt;http://www.martinfowler.com/eaaDev/EventSourcing.html?s_tact=C43202QW&lt;/A&gt;)&lt;BR /&gt;
Can Splunk be used as an event stream for that?&lt;/P&gt;

&lt;P&gt;Or are the above usecases better suited for other tools?&lt;/P&gt;

&lt;P&gt;//Roger&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2016 13:53:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-as-a-general-purpose-data-store/m-p/265624#M8336</guid>
      <dc:creator>rogeralsing</dc:creator>
      <dc:date>2016-09-05T13:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk as a general purpose data store?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-as-a-general-purpose-data-store/m-p/265625#M8337</link>
      <description>&lt;P&gt;Anyone?   .  &lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2016 09:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-as-a-general-purpose-data-store/m-p/265625#M8337</guid>
      <dc:creator>rogeralsing</dc:creator>
      <dc:date>2016-09-08T09:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk as a general purpose data store?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-as-a-general-purpose-data-store/m-p/265626#M8338</link>
      <description>&lt;P&gt;Question&amp;gt;  Splunk for general purpose free text searches or structural searches?&lt;BR /&gt;
Splunk works best with time series data, while your use case might be more similar to master data management that changes often with update operation.&lt;BR /&gt;
However you can all rows from DB everyday to Splunk using DB Connect Input Type = Batch if you want to, if it doesn't break your daily ingestion limit.  With this, you will get all your data into Splunk, updated everyday.&lt;/P&gt;

&lt;P&gt;Question&amp;gt; Can Splunk be used as an event stream for that? (event sourcing)&lt;BR /&gt;
For the event sourcing you've mentioned, try STREAMSTATS command, the result will change as you change the time range of your search&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2016 11:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-as-a-general-purpose-data-store/m-p/265626#M8338</guid>
      <dc:creator>haley_swarnapat</dc:creator>
      <dc:date>2016-09-08T11:39:06Z</dc:date>
    </item>
  </channel>
</rss>

