Getting Data In

Configure schedule job to export data from splunk to Hadoop

msplunk33
Path Finder

I need some documentation in configuring schedule job for exporting data from splunk to Hadoop using Splunk Hadoop connect. What are the prerequisites. I am new to hadoop. What are the different ways we can export data from splunk to hadoop.

Labels (1)
Tags (1)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

I have just developed alert actions which will be used to upload search results into AWS S3. I will upload TA to splunkbase.

————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust

@msplunk33 
The TA has been published and its available to public now.

————————————
If this helps, give a like below.
0 Karma

thambisetty
SplunkTrust
SplunkTrust

https://splunkbase.splunk.com/app/5273/#/overview

This app is pending approval and is not yet publicly visible. 

I will update here once app is published.

 

————————————
If this helps, give a like below.
0 Karma

msplunk33
Path Finder

Thank you. How can I download the  TA? Please share me the link.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Hadoop file system is completely different than AWS s3. 
May be you need to create a command or script to export splunk results to s3.

————————————
If this helps, give a like below.
0 Karma

thambisetty
SplunkTrust
SplunkTrust

You may find below link useful.

https://docs.splunk.com/Documentation/HadoopConnect/1.2.5/DeployHadoopConnect/AboutSplunkHadoopConne...

————————————
If this helps, give a like below.
0 Karma

msplunk33
Path Finder

I am using AWS S3 as the destination instead of Hadoop cluster. Any specific documentation for this.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

I have just developed alert actions which will be used to upload search results into AWS S3. I will upload TA to splunkbase.

————————————
If this helps, give a like below.

msplunk33
Path Finder

Thank you thambisetty

0 Karma
Get Updates on the Splunk Community!

Message Parsing in SOCK

Introduction This blog post is part of an ongoing series on SOCK enablement. In this blog post, I will write ...

Exploring the OpenTelemetry Collector’s Kubernetes annotation-based discovery

We’ve already explored a few topics around observability in a Kubernetes environment -- Common Failures in a ...

Use ‘em or lose ‘em | Splunk training units do expire

Whether it’s hummus, a ham sandwich, or a human, almost everything in this world has an expiration date. And, ...