<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Storing data in splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612036#M212807</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248856"&gt;@metylkinandrey&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk stores data in indexes that are folders containing the row data and the indexes, as you can read at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Indexer/Aboutindexesandindexers" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Indexer/Aboutindexesandindexers&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, answering to your questions:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Can I connect a DBMS to splunk using the example: ms sql, mysql in order to store data that falls into splunk.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Yes, you can save in Splunk every kind of data, from csv files to DB tables.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;What is the default database for splunk? &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk doesn't use a DB.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;What type of database is this database (relational or NoSQL).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Splunk doesn't use a DB: Splunk is a search engine that stores row data and indexes all of them making them searchable, for more infos see at &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Deploy/Datapipeline" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Deploy/Datapipeline&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;In addition it's also possible to extract some data from Splunk, putting them in MongoDB tables to make quicker some kind of searches.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;How does splunk store data, such as coming from json files.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk ingest files, parse them and then indexes every kind of files, also json.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hint to ask to a Splunk presale or to your trusted system integrator to show Splunk features.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Sep 2022 06:36:55 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-09-06T06:36:55Z</dc:date>
    <item>
      <title>Storing data in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612033#M212806</link>
      <description>&lt;P&gt;Good afternoon! I want to know how splunk stores data. I can't find detailed information.&lt;BR /&gt;Can I connect a DBMS to splunk using the example: ms sql, mysql in order to store data that falls into splunk.&lt;BR /&gt;What is the default database for splunk? What type of database is this database (relational or NoSQL).&lt;BR /&gt;How does splunk store data, such as coming from json files.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 14:41:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612033#M212806</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-09-06T14:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: Storing data in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612036#M212807</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248856"&gt;@metylkinandrey&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk stores data in indexes that are folders containing the row data and the indexes, as you can read at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Indexer/Aboutindexesandindexers" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Indexer/Aboutindexesandindexers&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, answering to your questions:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Can I connect a DBMS to splunk using the example: ms sql, mysql in order to store data that falls into splunk.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Yes, you can save in Splunk every kind of data, from csv files to DB tables.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;What is the default database for splunk? &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk doesn't use a DB.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;What type of database is this database (relational or NoSQL).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Splunk doesn't use a DB: Splunk is a search engine that stores row data and indexes all of them making them searchable, for more infos see at &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Deploy/Datapipeline" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Deploy/Datapipeline&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;In addition it's also possible to extract some data from Splunk, putting them in MongoDB tables to make quicker some kind of searches.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;How does splunk store data, such as coming from json files.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk ingest files, parse them and then indexes every kind of files, also json.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hint to ask to a Splunk presale or to your trusted system integrator to show Splunk features.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 06:36:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612036#M212807</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-06T06:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Storing data in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612038#M212808</link>
      <description>&lt;P&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 06:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612038#M212808</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-09-06T06:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Storing data in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612042#M212810</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248856"&gt;@metylkinandrey&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if my answer solves your need, please accept one answer for the other people of Community or tell us how we can help you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 07:28:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612042#M212810</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-06T07:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Storing data in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612044#M212811</link>
      <description>&lt;P&gt;Thank you very much for your reply!&lt;BR /&gt;I would also like to know the following.&lt;BR /&gt;When should splunk data be stored in an external database?&lt;BR /&gt;Do I understand correctly that this is not the best solution? And is it used only for operational information that needs quick access?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 07:48:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612044#M212811</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-09-06T07:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Storing data in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612045#M212812</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248856"&gt;@metylkinandrey&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me know: are you speaking of storing in Splunk information from a DB or store Splunk information in a DB?&lt;/P&gt;&lt;P&gt;the second one has no sense, data are stored in Splunk with an integrity check that guarantees that data aren't modified, in addition Splunk buckets (the elementare componentes of each Splunk index) are autocomplete componentes containing raw data and indexes for searching, so there isn't any reason to store Splunk Data in a DB, it's a non sense!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 07:53:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612045#M212812</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-06T07:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Storing data in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612046#M212813</link>
      <description>&lt;P&gt;Thank you! Yes, I meant the second option. And you can also tell about the first one? I think this case can also be.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 07:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612046#M212813</guid>
      <dc:creator>metylkinandrey</dc:creator>
      <dc:date>2022-09-06T07:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Storing data in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612049#M212814</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248856"&gt;@metylkinandrey&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in my opinion also the first option has no sense because there isn't any reason to store critical data outside a DB, I'd protect the DB.&lt;/P&gt;&lt;P&gt;Anyway, it's possible to extract data from a DB and to index them in Splunk, this is usually used to enrich other data already present in Splunk with information from a DB (e.g Asset Management).&lt;/P&gt;&lt;P&gt;It's possible to extract data from a DB in two main ways:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;using DB-Connect (&lt;A href="https://splunkbase.splunk.com/app/2686/" target="_blank"&gt;https://splunkbase.splunk.com/app/2686/&lt;/A&gt;), a free app created and maintained by Splunk that contains a jdbc client to run SQL queries and store results in Splunk,&lt;/LI&gt;&lt;LI&gt;running store procedures in the DB that save results in text files then read by Splunk.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 08:24:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Storing-data-in-Splunk/m-p/612049#M212814</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-09-06T08:24:41Z</dc:date>
    </item>
  </channel>
</rss>

