All Apps and Add-ons

How to import a SQL dump via Splunk DB Connect into an index?

bworrellZP
Communicator

Hello,

At this time, I do a nightly log import (stored in a SQL table) for one of our applications. Recently, new data sets were added to the SQL table from the app, going back to last year to help with log data.

Now I have been asked if I can refresh the Splunk data, which we use for alerts, graphs, lookups, etc. While I have updated all these for data going forward, not sure how to go get all the previous data without doing a new index or purging the current one, and doing a new SQL query 1,000,000 records at a time.

Does anyone know if I can import a SQL dump via DB Connect, into an index?

Thanks
Brian

0 Karma

richgalloway
SplunkTrust
SplunkTrust

AFAIK, DB Connect cannot import a SQL dump file. If you can get the dump into a CSV format, you can import that in the usual Splunk way. To avoid duplicate data, you'll need to delete the old data or use a new index.

---
If this reply helps you, Karma would be appreciated.
0 Karma

bworrellZP
Communicator

That is what I feared. Plan was to purge the existing data, then re-import, but to get the time frame requested, I need to pull in parts of over 20 million records, which means doing a lot of updates in the query, or finding another way.

Thanks for the validation though.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...