Splunk Search

Splunk logs in RedShift

ashishsecdev
Engager

Hi All,

I am trying to use RedShift to store all my Splunk logs, it it possible?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm going to say "no", without any official source to back that up. However, Splunk is not a traditional "big data" product, doesn't store it's data in a standard format, and doesn't use SQL to query data. All of those things would seem to disqualify Redshift.

---
If this reply helps you, Karma would be appreciated.

ashishsecdev
Engager

@richgalloway Check this out, do you think it would be full fledged solution?

https://fivetran.com/directory/splunk/amazon-redshift

0 Karma

richgalloway
SplunkTrust
SplunkTrust

As I read it, Fivetran merely copies Splunk data into Redshift. I don't see where Splunk can use the Redshift data. Consider using the free trial to see how it works, but understand that Splunk probably will not support you.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ashishsecdev
Engager

@richgalloway thanks for you response. Understood, I think we will rater go for some other solution and not RedShift.

0 Karma

ashishsecdev
Engager

Thanks, I was also thinking the same but wanted more clarity before I shoot up the email on this solution.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...