Getting Data In

What exactly do you mean by a provider in hunk?

sarnagar
Contributor

Hi ALL,

I was reading about HUNK on splunk.doc. They mention something about provider , ERP and configuration of this provider in indexes.conf....
Can someone please explain me what exactly is this provider??
Also How HUNK works using ERP??
Appreciate your help on this. Thankyou.

Tags (2)
1 Solution

jworthington_sp
Splunk Employee
Splunk Employee

Yep, the provider is simply whoever is hosting your data. It could be Hadoop, or it could be something like s3 or NoSQL.

An ERP - External Results Provider - is a process. It's provided by Splunk (unless you write your own), It uses info you configure about the provider to communicate with and gather the result from the Provider (i.e., Hadoop). When you configure a Provider, you are technically configuring an ERP as well, because that's the info the ERP uses.

I think this naming convention is a little confusing, I'll see if I can make the docs a little more clear.

View solution in original post

jworthington_sp
Splunk Employee
Splunk Employee

Yep, the provider is simply whoever is hosting your data. It could be Hadoop, or it could be something like s3 or NoSQL.

An ERP - External Results Provider - is a process. It's provided by Splunk (unless you write your own), It uses info you configure about the provider to communicate with and gather the result from the Provider (i.e., Hadoop). When you configure a Provider, you are technically configuring an ERP as well, because that's the info the ERP uses.

I think this naming convention is a little confusing, I'll see if I can make the docs a little more clear.

muebel
SplunkTrust
SplunkTrust

Hi sarnagar, The provider concept seems to indicate an "external resource provider" for the virtual indexes. I.E. hadoop, but they've kept this open ended enough to imply that other providers are possible.

Please let me know if this helps!

Ledion_Bitincka
Splunk Employee
Splunk Employee

Quick clarification ERP stands for "external results provider" - in Splunk the provider of results/events are the native indexes, in Hunk the results/events are provided by an external source, Hadoop, MongoDb, etc

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...