<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forwarding data from Splunk to some other  exernal SQL server ! in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-data-from-Splunk-to-some-other-exernal-SQL-server/m-p/327286#M93428</link>
    <description>&lt;P&gt;Hello Team , &lt;/P&gt;

&lt;P&gt;we have some requirement to send data to externally hosted SQL server not all but some fields data  captured from different log sources should be forwarded for display in  portal for some sort of mgmt reporting &lt;BR /&gt;
 for eg :- if we have email security logs integrated in splunk some fields required would be&lt;BR /&gt;&lt;BR /&gt;
 RECEIVED GOOD MAIL&lt;BR /&gt;
RECEIVED SPAM&lt;BR /&gt;
RECEIVED MALWARE&lt;BR /&gt;
and may be from firewall  these all fields inputs &lt;BR /&gt;
Count&lt;BR /&gt;
Threat/Content Type&lt;BR /&gt;
Action&lt;BR /&gt;
Threat/Content Name&lt;/P&gt;

&lt;P&gt;and from Vulnerability Mgmt   these fileds &lt;BR /&gt;
Asset IP Address&lt;BR /&gt;
Asset Names&lt;BR /&gt;
Site Name&lt;BR /&gt;
Asset OS Name &lt;/P&gt;

&lt;P&gt;These are just example inputs fields which may be considered . I am  bit puzzled  how can we do this to effectively send only required and limited data from splunk to SQL server &lt;/P&gt;</description>
    <pubDate>Thu, 25 Jan 2018 21:39:46 GMT</pubDate>
    <dc:creator>SunilMaharishi</dc:creator>
    <dc:date>2018-01-25T21:39:46Z</dc:date>
    <item>
      <title>Forwarding data from Splunk to some other  exernal SQL server !</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-data-from-Splunk-to-some-other-exernal-SQL-server/m-p/327286#M93428</link>
      <description>&lt;P&gt;Hello Team , &lt;/P&gt;

&lt;P&gt;we have some requirement to send data to externally hosted SQL server not all but some fields data  captured from different log sources should be forwarded for display in  portal for some sort of mgmt reporting &lt;BR /&gt;
 for eg :- if we have email security logs integrated in splunk some fields required would be&lt;BR /&gt;&lt;BR /&gt;
 RECEIVED GOOD MAIL&lt;BR /&gt;
RECEIVED SPAM&lt;BR /&gt;
RECEIVED MALWARE&lt;BR /&gt;
and may be from firewall  these all fields inputs &lt;BR /&gt;
Count&lt;BR /&gt;
Threat/Content Type&lt;BR /&gt;
Action&lt;BR /&gt;
Threat/Content Name&lt;/P&gt;

&lt;P&gt;and from Vulnerability Mgmt   these fileds &lt;BR /&gt;
Asset IP Address&lt;BR /&gt;
Asset Names&lt;BR /&gt;
Site Name&lt;BR /&gt;
Asset OS Name &lt;/P&gt;

&lt;P&gt;These are just example inputs fields which may be considered . I am  bit puzzled  how can we do this to effectively send only required and limited data from splunk to SQL server &lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 21:39:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-data-from-Splunk-to-some-other-exernal-SQL-server/m-p/327286#M93428</guid>
      <dc:creator>SunilMaharishi</dc:creator>
      <dc:date>2018-01-25T21:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding data from Splunk to some other  exernal SQL server !</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-data-from-Splunk-to-some-other-exernal-SQL-server/m-p/327287#M93429</link>
      <description>&lt;P&gt;Take a look at DB Connect:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/DBX/3.1.1/DeployDBX/HowSplunkDBConnectworks"&gt;http://docs.splunk.com/Documentation/DBX/3.1.1/DeployDBX/HowSplunkDBConnectworks&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Get the app here:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/2686/"&gt;https://splunkbase.splunk.com/app/2686/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 22:44:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-data-from-Splunk-to-some-other-exernal-SQL-server/m-p/327287#M93429</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-25T22:44:37Z</dc:date>
    </item>
  </channel>
</rss>

