Hi everyone,
Splunk noob here and I'm trying to import song logging data that I want to correlate with data from a SQL table so that I can include things in reports not in logs like people's names. I can import the logs easy enough, but I'm not sure what's the best way to go about getting the SQL data in. I know that I can import via a CSV and that there's also some SQL import scripts, but what would be the best way to import this?
Have you looked at this?
http://docs.splunk.com/Documentation/DBX/1.0.11/DeployDBX/Setupadatabaselookuptable
Unless I'm missing something, it doesn't look like this would work well with SplunkCloud or am I missing something?
The steps the use the web interface should work in Splunk Cloud. You cannot edit .conf files. You can ask tech support to edit them for you, but that shouldn't be necessary if the web interface worked. Of course, this assumes your SQL database can be reached from the cloud.
So basically, I'm limited to csv style import because this database is internal only. Thanks, though. I'll keep this in mind for the future.
Check out the Splunk DB Connect apps at https://splunkbase.splunk.com/app/958/ and https://splunkbase.splunk.com/app/2686/,