Deployment Architecture

If we have database connectors set up in Splunk, can we create data models using database queries?

hkosuru
Explorer

Hello,

We have database connectors set up in Splunk to run database queries. Can you create Data Models using database queries?

Thanks,
Bindu

0 Karma

niemesrw
Path Finder

I'm not entirely sure what you're trying to do here, but we have done the following:

  1. use db connect and run sql query to dump out hashes of files detected by symantec (sql database)
  2. db connect populates an index=detected_hashes
  3. created CIM-compatible fields mapping the database fields to the inventory datamodel (inventory datamodel has constraint=detected_hashes)
  4. inventory datamodel can be queried to return information in the detected_hashes index

all DM commands (like acceleration) work fine.

0 Karma

muebel
SplunkTrust
SplunkTrust

you using db connect v1 or v2?

0 Karma

hkosuru
Explorer

currently using v1. planning to move to v2

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...