Hi,
I'm new to Splunk DB connector. Having Splunk on-prem version and trying to pull data from Snowflake audit logs and push to cribl.io (for log optimization purpose and reducing log size).
As Cribl.io doesn't have connector for Snowflake (and not in near roadmap), wondering if I use Splunk DB connect to read data from Snowflake and send to Cribl.io followed by sending to destination i.e. Splunk (for log monitoring and alerting)
Question: Would this be "double hop" to Splunk, if yes, any Splunk charges be applicable while Splunk DB connect reading from Snowflake and sending to Cribl.io?
Thank you!
Avi
Hi, yes I've tested this use case in env and things are working as expected. I was more concerned about hidden charges when we start blowing things. Thanks for making this straight for me. It's helpful.
Hi @avifyi
Good day to you. thanks for the interesting question.
>>>cribl.io (for log optimization purpose and reducing log size)
1) May we know some details about how much data (approx) you are having the plan?
-------from Splunk DB Connector to cribl.io
2) may we know, approximately how much optimization and log size reduction you planning to achieve using the cribl.io?
3) though its doable task, it may not be necessary at all at sometimes 😉
4) from where the Splunk DB Connector is reading the logs? lets say you have a DB X.
X DB ----- > Splunk DB Connector ----- > Cribl.io ------ > back to Splunk
instead of this, maybe plan about
X DB ------> cribl.io-------> to Splunk
Thanks and Best Regards
(PS - my karma stats - given 2000+ and received 500. thanks for reading )