Using mySQL data in Splunk with Splunk Search Language
Hi
I am currently using the Splunk DB Connect App. I have set up all of my Inputs and I am querying the tables in Splunk but I would prefer to just use the Splunk Search Language, is this possible?
Will I be able to pull together a dashboard with correlations from different data sources?
Hi Olivia,
It sounds like you've created a database connection and you're using the query page to run SQL queries?
If this is the case, you'll probably want to create an input to index the SQL results.
Here's a very brief process on on-boarding SQL data sources.
DB Connect V2 (Explorer tab)
Now, this is the part where you actually create the input
DBConnect V2 (Operations tab)
Give it a minute or 2, and start searching index=your_index
If you haven't seen them already, here's our guide on DB Connect: http://docs.splunk.com/Documentation/DBX/2.4.0/DeployDBX/AboutSplunkDBConnect
If you want to debug your connections, take a look at splunkd.log, or dbx2.log
Thanks