Getting Data In

Any S3 input could support parquet format?

xmeng
Loves-to-Learn Lots

Hi, I met an input issue about s3, which stays not in a aws security lake. Is that possible to use Splunk addon for aws to ingest s3 bucket with parquet formatted files? 

 

Labels (1)
0 Karma

fholyfield
New Member

S3SPL Add-On for Splunk enables your data stored in S3 for immediate insight using custom Splunk commands. The source of the data does not matter, as long as it is stored in S3 and can be queried using S3 Select. This includes JSON, CSV, Parquet and even files written by Splunk Ingest Actions.

S3SPL provides the following functionality to Splunk users:

  • Query S3 using S3Select in an ad-hoc fashion using WHERE statements
  • Save queries and share them with other users
  • Configure queries to manage timestamps based on defined field names automatically
  • Configure queries with replacements to adapt queries to the current requirement on the fly
  • Create queries and preview results using an interactive workbench

In addition, S3SPL provides an admin section that allows the management of multiple buckets and saved queries. Finally, a comprehensive access control system based on Splunk capabilities and roles allows for granular access control from Splunk to buckets and prefixes within them.

0 Karma

jmartin_pro
Explorer

I am also looking for a solution that supports parquet format

0 Karma

xmeng
Loves-to-Learn Lots

Or only the data manager will be the only solution for this kind of input?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...