Getting Data In

Is there a dbconnect alternative that doesn't consume so much license?

davel1333
Engager

Is there an alternative to dbconnect for getting RDBMS data into Splunk?
I'm having some errors due to moving the data because my DB keeps changing, and the data in Splunk is not always up to date.
Also, I can't keep indexing all the data because this is consuming a lot of license.

nabeel652
Builder

The best option will be running scripts and just looking for the changed bits and sending to Splunk though HEC (or writing to file and monitoring). then dedup on the "unique key" in your data will give you all unchanged old records + changed new records. However, there is no out of the box solution for this other than dbconnect

richgalloway
SplunkTrust
SplunkTrust

Use the Rising Column feature of DB Connect to index only new data and save on your license.
Another option is to write your own modular input that uses JDBC to read the database the way to want to.

---
If this reply helps you, Karma would be appreciated.
0 Karma

barriersbill
Explorer

yea the rising column should work, unless there isn't one then don't know what to do

0 Karma

vishaltaneja070
Motivator

@davel1333: If you don't want to consume licence or store data, then you can use dbquery command.

0 Karma

skalliger
Motivator

Depends. Which DB are we talking about?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...