Getting Data In

Extracting of SQLite

jiamin94
Engager

Hello i would like to extract SQLite data and pass to splunk using shell script.
Anyone have any idea how to write the shell script?

Tags (3)

musskopf
Builder

Have a look on a solution I found to use sqlite3 inside python lookup scripts:

http://answers.splunk.com/answers/109009/splunk6-django-app-importing-sqlite

Once you have the sqlite module installed you could write a python script to "SELECT" your data from the sqlite3 file. If you use a script input in Splunk, your script just just needs to output something like that to the screen:

2014-06-24 14:00:12 +10:00, table="table01", columnA="value from clA row1", columnB="value from clB row1"
2014-06-24 14:00:13 +10:00, table="table01", columnA="value from clA row2", columnB="value from clB row2"

Make sure you handle the exceptions on your script and output errors to stderr so it won't index those messages.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...