<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk db connect in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483310#M193325</link>
    <description>&lt;P&gt;Thank you very much David &lt;BR /&gt;
it's very helpfull ! &lt;/P&gt;</description>
    <pubDate>Wed, 15 Jan 2020 14:58:34 GMT</pubDate>
    <dc:creator>aalaa</dc:creator>
    <dc:date>2020-01-15T14:58:34Z</dc:date>
    <item>
      <title>splunk db connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483305#M193320</link>
      <description>&lt;P&gt;Hello community , &lt;/P&gt;

&lt;P&gt;I would like to know where splunk db connect stored data ? &lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 10:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483305#M193320</guid>
      <dc:creator>aalaa</dc:creator>
      <dc:date>2020-01-15T10:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: splunk db connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483306#M193321</link>
      <description>&lt;P&gt;Sorry, but your question is not clear to me. Do you mean where does the Splunk DB Connect stores it's data that is being queried from a database table? Or where does the Splunk DB Connect saves it's config files. Please clarify. &lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 12:50:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483306#M193321</guid>
      <dc:creator>PvandenHondel</dc:creator>
      <dc:date>2020-01-15T12:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: splunk db connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483307#M193322</link>
      <description>&lt;P&gt;Hi @aalaa,&lt;/P&gt;

&lt;P&gt;DBconnect doesn't store any data. It allows you to create a connection with Data Bases and collect the data from there or use the DB as a lookup.&lt;/P&gt;

&lt;P&gt;If you have a DB input setup, the all you have to do is look for the index where it's writing the data and you'll have everything there. If there is no DB input created then you're not indexing data at all and it's all still on your data base or in some lookup file.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 13:05:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483307#M193322</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2020-01-15T13:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: splunk db connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483308#M193323</link>
      <description>&lt;P&gt;Thank you David , and what about the other data ? how splunk store it ? &lt;BR /&gt;
I would like to know how splunk store data &lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 13:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483308#M193323</guid>
      <dc:creator>aalaa</dc:creator>
      <dc:date>2020-01-15T13:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: splunk db connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483309#M193324</link>
      <description>&lt;P&gt;You're welcome @aalaa.&lt;/P&gt;

&lt;P&gt;This document explains how Splunk stores data, what the index structure is and what the buckets inside an index are: &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/HowSplunkstoresindexes"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/HowSplunkstoresindexes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;All your indexed data is stored on your indexers and the structure of each data index is as the one you'll see described in the link above.&lt;/P&gt;

&lt;P&gt;Let me know if that helps and if there's anything I missed.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 13:53:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483309#M193324</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2020-01-15T13:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: splunk db connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483310#M193325</link>
      <description>&lt;P&gt;Thank you very much David &lt;BR /&gt;
it's very helpfull ! &lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 14:58:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-db-connect/m-p/483310#M193325</guid>
      <dc:creator>aalaa</dc:creator>
      <dc:date>2020-01-15T14:58:34Z</dc:date>
    </item>
  </channel>
</rss>

