<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk DB connect: How does it work when storing/indexing data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-DB-connect-How-does-it-work-when-storing-indexing-data/m-p/360574#M65765</link>
    <description>&lt;P&gt;DB connect will not only pull logs from any database and search data but also it can push changes back to Database from splunk , this is major difference.&lt;BR /&gt;
Also in DB connect license utilisation concept remains same&lt;/P&gt;</description>
    <pubDate>Tue, 26 Feb 2019 14:27:06 GMT</pubDate>
    <dc:creator>rakesh44</dc:creator>
    <dc:date>2019-02-26T14:27:06Z</dc:date>
    <item>
      <title>Splunk DB connect: How does it work when storing/indexing data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-DB-connect-How-does-it-work-when-storing-indexing-data/m-p/360572#M65763</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;

&lt;P&gt;First of all, thank you for reading this question.&lt;BR /&gt;
I am being asked to monitor a new data source (ServiceNow) to track our Incident and Change tickets for ITIL purposes.&lt;/P&gt;

&lt;P&gt;The way to go with ServiceNow is DB connect and I am a newbie using DB connect, so in order to calculate license required and storage, I would like to understand by asking the following question:&lt;/P&gt;

&lt;P&gt;ServiceNow offers both syslog and DB connection to retrieve the Incidents and Change tickets fields and we are interested in how opened the ticket, assignee group, description, blah, blah blah.&lt;/P&gt;

&lt;P&gt;What are the advantages of doing it DB instead of SYSLog and vice-versa?&lt;BR /&gt;
Is the same indexing ratio and licensing/storage consumption doing it in DB connect than Syslog? or it varies? &lt;BR /&gt;
Which one will you go and why?&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 23:54:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-DB-connect-How-does-it-work-when-storing-indexing-data/m-p/360572#M65763</guid>
      <dc:creator>jesusgalloEMC</dc:creator>
      <dc:date>2018-02-07T23:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect: How does it work when storing/indexing data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-DB-connect-How-does-it-work-when-storing-indexing-data/m-p/360573#M65764</link>
      <description>&lt;P&gt;For what i use, DB Connect is to read data from Bases like Oracle, Mysql, etc. After the first config. you can use searchs like:&lt;/P&gt;

&lt;P&gt;| dbquery "DB-NAME" "select * from dual"&lt;/P&gt;

&lt;P&gt;And you can even summary those informations, so when you need to run a query in the DB and save that info in a csv file or a index.&lt;/P&gt;

&lt;P&gt;Now syslog is just data being indexed to your splunk, it affects the license and you can read it from a index.&lt;/P&gt;

&lt;P&gt;index=my_syslog | table *&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 01:11:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-DB-connect-How-does-it-work-when-storing-indexing-data/m-p/360573#M65764</guid>
      <dc:creator>felipesewaybric</dc:creator>
      <dc:date>2018-02-08T01:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect: How does it work when storing/indexing data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-DB-connect-How-does-it-work-when-storing-indexing-data/m-p/360574#M65765</link>
      <description>&lt;P&gt;DB connect will not only pull logs from any database and search data but also it can push changes back to Database from splunk , this is major difference.&lt;BR /&gt;
Also in DB connect license utilisation concept remains same&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 14:27:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-DB-connect-How-does-it-work-when-storing-indexing-data/m-p/360574#M65765</guid>
      <dc:creator>rakesh44</dc:creator>
      <dc:date>2019-02-26T14:27:06Z</dc:date>
    </item>
  </channel>
</rss>

