All Apps and Add-ons

Merging data from a database into splunk

brettcave
Builder

With splunk, I would like to correlate event-driven data with data from a database. I am able to export from a database, say Mongo, to JSON and then import that data into splunk (or MySQL to csv)

What is the best approach to merging data into splunk?

The first approach I have in mind is to just import the full database (and possibly delete older uploads via | delete) to run reports on, but ideally, I would like to try merge data in.

Any other approaches to this that comes to mind?

Tags (3)
0 Karma
1 Solution

emotz
Splunk Employee
Splunk Employee

you might want to take a look at this app:
http://splunk-base.splunk.com/apps/36664/splunk-mysql-connector

If the data in the database changes frequently, using a lookup is probably more efficient as you are not duplicating the data in Splunk. If the data is more static and many more correlations or fields are required to join with other machine data, you could consider indexing the data from a file that you are already exporting.

View solution in original post

emotz
Splunk Employee
Splunk Employee

you might want to take a look at this app:
http://splunk-base.splunk.com/apps/36664/splunk-mysql-connector

If the data in the database changes frequently, using a lookup is probably more efficient as you are not duplicating the data in Splunk. If the data is more static and many more correlations or fields are required to join with other machine data, you could consider indexing the data from a file that you are already exporting.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...