I am using the DB Connect app to connect to a MYSQL database and input the data from a table.
What sourcetype should I use for MySQL data in the Database Input:
Also the datetime fields in the MySQL data like "2013-09-24 21:31:13" appear as "1385819882.000" in Splunk - is this format to do with the sourcetype and how can I get Splunk to keep the original format?
Can you post the splunk\etc\apps\dbx\local\inputs.conf stanza for this MySQL input?
To view the raw data in Splunk you run a search that pulls the data from this input and then table it to _raw
search for MySQL data | table _raw
Is it possible to view the rawdata in Splunk that is returned by a MySQL query run from Splunk?
The MySQL data has some datetime fields like "2013-09-24 21:31:13", but these appear as "1385819882.000" in Splunk - how can I get Splunk to keep the original datetime format?
Is it possible to view the rawdata in Splunk that is returned by a MySQL query run from Splunk?
The MySQL data has some datetime fields like "2013-09-24 21:31:13", but these appear as "1385819882.000" in Splunk - how can I get Splunk to keep the original datetime format?
You'll probably get good results with KV. Experiment in a separate index until you get the results you want.
If you click on the DB Query button in the DB Connect app you can enter a query and see what would be indexed.
To get the datetime format you want, use CONVERT(datetime, column, 120)
.
Is it possible to view the rawdata in Splunk that is returned by a MySQL query run from Splunk?
The MySQL data has some datetime fields like "2013-09-24 21:31:13", but these appear as "1385819882.000" in Splunk - how can I get Splunk to keep the original datetime format?