- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If we have database connectors set up in Splunk, can we create data models using database queries?
hkosuru
Explorer
04-15-2016
07:46 AM
Hello,
We have database connectors set up in Splunk to run database queries. Can you create Data Models using database queries?
Thanks,
Bindu
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
niemesrw
Path Finder
04-18-2016
08:51 PM
I'm not entirely sure what you're trying to do here, but we have done the following:
- use db connect and run sql query to dump out hashes of files detected by symantec (sql database)
- db connect populates an index=detected_hashes
- created CIM-compatible fields mapping the database fields to the inventory datamodel (inventory datamodel has constraint=detected_hashes)
- inventory datamodel can be queried to return information in the detected_hashes index
all DM commands (like acceleration) work fine.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
muebel

SplunkTrust
04-15-2016
02:16 PM
you using db connect v1 or v2?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hkosuru
Explorer
04-15-2016
05:36 PM
currently using v1. planning to move to v2
