Splunk Enterprise

SplunkDB Connect and MongoDB on prem

fabrizioalleva
Path Finder

Hi all,

I need to use SplunkDB connect to connect to a MongoDB on prem instance.

I've installed Splunk DBX Add-on for MongoDB  but I understand that it works only with Atlas MongoDB and not with Mongo on prem installation.

I tried to follow this suggestion

https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-Splunk-DB-Connect-to-sear...

but the format of stanza is  quite different.

 I try to create a connection using the MongoDB Atlas Connection Type, I receive this error:

Command failed with error 40324 (Location40324): 'Unrecognized pipeline stage name: '$sql'

Any suggestion ?

Fabrizio

 

 

Labels (1)
0 Karma

kiran_panchavat
Influencer

@fabrizioalleva 

Connecting Splunk DB Connect to an on-premises MongoDB instance requires some additional steps compared to using MongoDB Atlas.

To connect to your on-premises MongoDB, you’ll need the MongoDB JDBC driver. You can download it from https://unityjdbc.com/download.php?type=mongodb  . Make sure to obtain the mongodb_unityjdbc_full.jar from the installation folder.

Then, you can configure a JDBC Connection

https://unityjdbc.com/mongojdbc/setup/mongodb_jdbc_splunk_dbconnect_v3.pdf 

I hope this helps, if any reply helps you, you could add your upvote/karma points to that reply, thanks.

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...