Knowledge Management

Splunk SQL query

rahul2gupta
Path Finder

Hi @gcusello ,

Is it possible to run a SQL query from Splunk search bar to a SQL server? i.e. I want to run a SQL query against server abc1sql07.

Is this possible ? if so, what permission do we need to setup on SQL server to ensure Splunk has permission to query the database?

Regards,

Rahul

0 Karma

anilchaithu
Builder

@rahul2gupta 

It is possible to query database from Splunk.

  • You need read permissions to the database.
  • You need to install splunk app for dbconnect on splunk

The syntax to run this query is

 

| dbxquery connection="connection_name" query="select ...."

 

 

Hope this helps

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...