Anyone know how to do this? I want to read Splunk data directly through hive, without archiving data to hadoop. Thanks.
Hello. I have successfully queried hive with Splunk.
https://docs.splunk.com/Documentation/Splunk/7.2.3/HadoopAnalytics/ConfigureHivepreprocessor
In a nutshell
Hello. I have successfully queried hive with Splunk.
https://docs.splunk.com/Documentation/Splunk/7.2.3/HadoopAnalytics/ConfigureHivepreprocessor
In a nutshell
Thanks a lot. will try this. Just want to make sure, the splunk data here is not archived to Hadoop. We can directly map from Hive to Splunk data model.
Yes you associate a virtual index with a Hive table.