All Apps and Add-ons

MongoDb data indexing

sssid
New Member

I am planning to use splunk for visualizing my data and could use some help modelling it .

  • i have some json data stored in mongodb that i need to access in splunk .
  • Data reaches upto 1 TB per day .
  • I need to fetch, process and index this data so it can be viewed in splunk.

My question is with the fetching the data . What is the best way to fetch this data periodically ? I need to fetch data from mongodb for a particular time frame . Ie this is not real time streaming data .

After I specify data sources using hunk , how do i index the data for specific time ranges ?

Should i create an intermediary application (node.js or java) just for fetching and indexing the data periodically ?

0 Karma

puneethgowda
Communicator

But what are the configuration needed to bring the data into Splunk from mangodb

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

You can either use the Hunk App for MongoDB or DB Connect with JDBC to MongoDB.
With Hunk App for MongoDB:
in the search use: index=mongoVIX | collect my-local-splunk-index
or
set a schedule search and send the data to my-local-splunk-index

With DB Connect:
Setup Database Input based on rising column or batch. In both cases the data will be sent to a local Splunk index.

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...