<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What sourcetype should be used input MySQL data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164073#M33226</link>
    <description>&lt;P&gt;You'll probably get good results with KV.  Experiment in a separate index until you get the results you want.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Dec 2013 17:04:19 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2013-12-03T17:04:19Z</dc:date>
    <item>
      <title>What sourcetype should be used input MySQL data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164072#M33225</link>
      <description>&lt;P&gt;I am using the DB Connect app to connect to a MYSQL database and input the data from a table. &lt;/P&gt;

&lt;P&gt;What sourcetype should I use for MySQL data in the Database Input:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;dbmon:kv&lt;/LI&gt;
&lt;LI&gt;dbmon:mkv&lt;/LI&gt;
&lt;LI&gt;or some other?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Also the datetime fields in the MySQL data like "2013-09-24 21:31:13" appear as "1385819882.000" in Splunk - is this format to do with the sourcetype and how can I get Splunk to keep the original format?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 12:27:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164072#M33225</guid>
      <dc:creator>ti786</dc:creator>
      <dc:date>2013-12-03T12:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: What sourcetype should be used input MySQL data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164073#M33226</link>
      <description>&lt;P&gt;You'll probably get good results with KV.  Experiment in a separate index until you get the results you want.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 17:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164073#M33226</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2013-12-03T17:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: What sourcetype should be used input MySQL data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164074#M33227</link>
      <description>&lt;P&gt;Is it possible to view the rawdata in Splunk that is returned by a MySQL query run from Splunk?&lt;/P&gt;

&lt;P&gt;The MySQL data has some datetime fields like "2013-09-24 21:31:13", but these appear as "1385819882.000" in Splunk - how can I get Splunk to keep the original datetime format?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 18:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164074#M33227</guid>
      <dc:creator>ti786</dc:creator>
      <dc:date>2013-12-03T18:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: What sourcetype should be used input MySQL data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164075#M33228</link>
      <description>&lt;P&gt;Is it possible to view the rawdata in Splunk that is returned by a MySQL query run from Splunk?&lt;/P&gt;

&lt;P&gt;The MySQL data has some datetime fields like "2013-09-24 21:31:13", but these appear as "1385819882.000" in Splunk - how can I get Splunk to keep the original datetime format?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 18:57:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164075#M33228</guid>
      <dc:creator>ti786</dc:creator>
      <dc:date>2013-12-03T18:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: What sourcetype should be used input MySQL data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164076#M33229</link>
      <description>&lt;P&gt;Is it possible to view the rawdata in Splunk that is returned by a MySQL query run from Splunk?&lt;/P&gt;

&lt;P&gt;The MySQL data has some datetime fields like "2013-09-24 21:31:13", but these appear as "1385819882.000" in Splunk - how can I get Splunk to keep the original datetime format?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 18:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164076#M33229</guid>
      <dc:creator>ti786</dc:creator>
      <dc:date>2013-12-03T18:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: What sourcetype should be used input MySQL data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164077#M33230</link>
      <description>&lt;P&gt;Can you post the splunk\etc\apps\dbx\local\inputs.conf stanza for this MySQL input?&lt;/P&gt;

&lt;P&gt;To view the raw data in Splunk you run a search that pulls the data from this input and then table it to _raw&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;search for MySQL data | table _raw&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 19:16:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164077#M33230</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-03T19:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: What sourcetype should be used input MySQL data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164078#M33231</link>
      <description>&lt;P&gt;If you click on the DB Query button in the DB Connect app you can enter a query and see what would be indexed.&lt;/P&gt;

&lt;P&gt;To get the datetime format you want, use &lt;CODE&gt;CONVERT(datetime, column, 120)&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 20:58:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-be-used-input-MySQL-data/m-p/164078#M33231</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2013-12-03T20:58:37Z</dc:date>
    </item>
  </channel>
</rss>

