Splunk Search

What are some best practices to import data from an Oracle database table (not database logs)?

scottrudy
Engager

I have a very large Oracle database table that is being used as a log sink for an application. There is high transaction throughput on this table. I would like to get the data in this table (not about this table) into Splunk as real time as possible. Unfortunately, I do not have access to the source in order to add a log sink directly to Splunk. I realize I could read the data and move it in batches, but I'm wondering if there are any less-intensive options such as transaction log replication. What is the best practice for moving this type of data?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

AFAIK, the only method Splunk has for reading a SQL database is the DB Connect app.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...