All Apps and Add-ons

How to import a SQL dump via Splunk DB Connect into an index?

bworrellZP
Communicator

Hello,

At this time, I do a nightly log import (stored in a SQL table) for one of our applications. Recently, new data sets were added to the SQL table from the app, going back to last year to help with log data.

Now I have been asked if I can refresh the Splunk data, which we use for alerts, graphs, lookups, etc. While I have updated all these for data going forward, not sure how to go get all the previous data without doing a new index or purging the current one, and doing a new SQL query 1,000,000 records at a time.

Does anyone know if I can import a SQL dump via DB Connect, into an index?

Thanks
Brian

0 Karma

richgalloway
SplunkTrust
SplunkTrust

AFAIK, DB Connect cannot import a SQL dump file. If you can get the dump into a CSV format, you can import that in the usual Splunk way. To avoid duplicate data, you'll need to delete the old data or use a new index.

---
If this reply helps you, Karma would be appreciated.
0 Karma

bworrellZP
Communicator

That is what I feared. Plan was to purge the existing data, then re-import, but to get the time frame requested, I need to pull in parts of over 20 million records, which means doing a lot of updates in the query, or finding another way.

Thanks for the validation though.

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...