<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk DB Connect - data formating in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-DB-Connect-data-formating/m-p/507985#M86447</link>
    <description>&lt;P&gt;Hey everyone!&lt;/P&gt;&lt;P&gt;Lately we had an unfortunate incident were most of our logs were deleted from splunk. Luckily we saved the same data at our PostgreSQL DB.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;To restore those logs, I want to export the PostgreSQL data via Splunk DB Connect.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read about the app and it looks like it can solve most of my concerns. My main issue that I couldn't find solution for is data formating.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;To make it backwards compatible to our logs format, I want to parse the db table rows by:&lt;/P&gt;&lt;P&gt;1. Sending the data to splunk as a json&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Add some custom key:value pairs (that are based / can be calculated from the database row)&lt;/P&gt;&lt;P&gt;3. Not include specific table columns&lt;/P&gt;&lt;P&gt;4. Append metadata to the logs (already found that this point is possible)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way of achieving those wishes without working with raw SQL?&lt;/P&gt;&lt;P&gt;If not, can I see an example of raw SQL that generates the wanted splunk log?&lt;/P&gt;&lt;P&gt;Also, is there any other way of exporting &amp;amp; importing data from postgres to splunk that can solve this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jul 2020 08:31:28 GMT</pubDate>
    <dc:creator>Acxon1</dc:creator>
    <dc:date>2020-07-08T08:31:28Z</dc:date>
    <item>
      <title>Splunk DB Connect - data formating</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-DB-Connect-data-formating/m-p/507985#M86447</link>
      <description>&lt;P&gt;Hey everyone!&lt;/P&gt;&lt;P&gt;Lately we had an unfortunate incident were most of our logs were deleted from splunk. Luckily we saved the same data at our PostgreSQL DB.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;To restore those logs, I want to export the PostgreSQL data via Splunk DB Connect.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read about the app and it looks like it can solve most of my concerns. My main issue that I couldn't find solution for is data formating.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;To make it backwards compatible to our logs format, I want to parse the db table rows by:&lt;/P&gt;&lt;P&gt;1. Sending the data to splunk as a json&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Add some custom key:value pairs (that are based / can be calculated from the database row)&lt;/P&gt;&lt;P&gt;3. Not include specific table columns&lt;/P&gt;&lt;P&gt;4. Append metadata to the logs (already found that this point is possible)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way of achieving those wishes without working with raw SQL?&lt;/P&gt;&lt;P&gt;If not, can I see an example of raw SQL that generates the wanted splunk log?&lt;/P&gt;&lt;P&gt;Also, is there any other way of exporting &amp;amp; importing data from postgres to splunk that can solve this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 08:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-DB-Connect-data-formating/m-p/507985#M86447</guid>
      <dc:creator>Acxon1</dc:creator>
      <dc:date>2020-07-08T08:31:28Z</dc:date>
    </item>
  </channel>
</rss>

