All Apps and Add-ons

Using splunk to check your log against database

c0mrade
Explorer

Hello all, I'm a new splunk user and I'm not familiar yet with all its features. I have a rather unusual(or not) thing in mind to do with splunk.

I have a jboss application server log, in which I have all request towards 3rd party service logged. Each request has requestId which could be extracted.

I want to use those extracted requestIds to query the 3rd party service database and to compare the results which I get with those in my log.

I realize that I'll have to do some scripting to do this, my question is : is splunk overhead for this? or I'd be better of writing some script for this.

Anyone had similar expiriences?

Tags (2)
0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

You can use splunk to pull entries from a database, but it will require the input you setup be a scripted input. So, yes, you can do it. However, as you suspected, it will require some scripting to do accomplish the task.

There have been a few posts about this over the last week which I find you'll probably find to be helpful and applicable to your particular scenario.

http://splunk-base.splunk.com/answers/23846/how-do-i-setup-an-input-for-sql-data?page=1#23857

http://splunk-base.splunk.com/answers/23772/index-a-db-log

View solution in original post

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

You can use splunk to pull entries from a database, but it will require the input you setup be a scripted input. So, yes, you can do it. However, as you suspected, it will require some scripting to do accomplish the task.

There have been a few posts about this over the last week which I find you'll probably find to be helpful and applicable to your particular scenario.

http://splunk-base.splunk.com/answers/23846/how-do-i-setup-an-input-for-sql-data?page=1#23857

http://splunk-base.splunk.com/answers/23772/index-a-db-log

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...