I need to export the events from Splunk to a Hadoop environment, so I am thinking of using the Splunk Hadoop Connect app for this purpose. Actually, our Splunk is installed on Windows servers. I came across various Splunk Hadoop Connect app documentations and find out that we cannot use the app in a Windows environment.
You must deploy Splunk Hadoop Connect on a *nix instance of Splunk Enterprise.
Anyone done this scenario before? Should we need to create a new nix Splunk instances? After creating the new nix environment, can we directly install the app on the search head?
You may want to test Cygwin (linux environment in windows)
Also, Although not supported and was not tested by Splunk, is to follow these steps to install Hadoop on windows - http://wiki.apache.org/hadoop/Hadoop2OnWindows