would it be possible to read directly from Mysql schema instead of snort log file , since i have few sensors logging into Splunk machine Mysql db?
Thanks
This is not supported at this time, and likely won't be anytime soon either.
The idea of the Splunk for Snort app is to operate on Snort log data within Splunk's index. Having it operate on data in an external SQL database would require a scripted input that first reads it out of the database, transforms it into some text format (for instance one of the formats already supported by the app) and then feeds it into Splunk. This is a somewhat backwards way of doing things, and there are a bunch of other tools that can operate directly on an SQL database containing Snort events instead, like for instance Snorby, Aanval (I think?), BASE/ACID/SnortCenter, and others.
That said, I don't have anything against the idea itself so if someone were to add this functionality to the app I wouldn't mind including it in the "official" package.