Anyone know how to do this? I want to read Splunk data directly through hive, without archiving data to hadoop. Thanks.
Hello. I have successfully queried hive with Splunk.
In a nutshell
View solution in original post
Thanks a lot. will try this. Just want to make sure, the splunk data here is not archived to Hadoop. We can directly map from Hive to Splunk data model.
Yes you associate a virtual index with a Hive table.