All Apps and Add-ons

MongoDb data indexing

sssid
New Member

I am planning to use splunk for visualizing my data and could use some help modelling it .

  • i have some json data stored in mongodb that i need to access in splunk .
  • Data reaches upto 1 TB per day .
  • I need to fetch, process and index this data so it can be viewed in splunk.

My question is with the fetching the data . What is the best way to fetch this data periodically ? I need to fetch data from mongodb for a particular time frame . Ie this is not real time streaming data .

After I specify data sources using hunk , how do i index the data for specific time ranges ?

Should i create an intermediary application (node.js or java) just for fetching and indexing the data periodically ?

0 Karma

puneethgowda
Communicator

But what are the configuration needed to bring the data into Splunk from mangodb

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

You can either use the Hunk App for MongoDB or DB Connect with JDBC to MongoDB.
With Hunk App for MongoDB:
in the search use: index=mongoVIX | collect my-local-splunk-index
or
set a schedule search and send the data to my-local-splunk-index

With DB Connect:
Setup Database Input based on rising column or batch. In both cases the data will be sent to a local Splunk index.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...