Hi,
Yesterday I upgraded Splunk to 6.0.1 (thank god) and configured DB Connect to fetch from a database.
I am trying to combine this database data with information coming in from log sources in my Search app. Any recommendation on the easiest way to do this?
-Can I send DB Connect data to Search?
-Can I search DB Connect data from within Search without having to send to the Search index?
Thanks,
B
Yes, you can use the DB Connect search commands and lookups. The most common usage of DB Connect is to use lookups from a database table to enrich machine data.
That is well documented here:
Setup a lookup table
The other option is to use the DB connect search commands such as dbquery:
DB Connect search commands
As an example, you could use dbquery on it's own or you could join it, use it in a subsearch, append it and more.
Here is what the dbquery command looks like:
| dbquery ASSET_DB "SELECT id,name, ip_address,owner,last_update FROM hosts WHERE active = 1"
That should be pretty easy to understand.
Yes, you can use the DB Connect search commands and lookups. The most common usage of DB Connect is to use lookups from a database table to enrich machine data.
That is well documented here:
Setup a lookup table
The other option is to use the DB connect search commands such as dbquery:
DB Connect search commands
As an example, you could use dbquery on it's own or you could join it, use it in a subsearch, append it and more.
Here is what the dbquery command looks like:
| dbquery ASSET_DB "SELECT id,name, ip_address,owner,last_update FROM hosts WHERE active = 1"
That should be pretty easy to understand.
Adding a input type gave me exactly what I needed and even parsed the fields for me. This tool just got so much more versatile. Thanks.
Great! Thanks okrabbe
Not sure I understand. Do you want to send data from a database input to the main index? Or something else?