Knowledge Management

Mapping Splunk data models to Hive

sabburisplunk
New Member

Anyone know how to do this? I want to read Splunk data directly through hive, without archiving data to hadoop. Thanks.

Tags (1)
0 Karma
1 Solution

burwell
SplunkTrust
SplunkTrust

Hello. I have successfully queried hive with Splunk.

https://docs.splunk.com/Documentation/Splunk/7.2.3/HadoopAnalytics/ConfigureHivepreprocessor

In a nutshell

  • you will need a license for Hadoop Analytics
  • You either use the metastore capability or you tell Splunk what datatype each Hive field
  • You tell Splunk the database and table name for Hive
  • You tell Splunk the path to the Hive data and what the db paths will look like
  • Splunk will run MUCH faster if your data has partitions

- setting up the provider can be a little bewildering if you have never done it

View solution in original post

0 Karma

burwell
SplunkTrust
SplunkTrust

Hello. I have successfully queried hive with Splunk.

https://docs.splunk.com/Documentation/Splunk/7.2.3/HadoopAnalytics/ConfigureHivepreprocessor

In a nutshell

  • you will need a license for Hadoop Analytics
  • You either use the metastore capability or you tell Splunk what datatype each Hive field
  • You tell Splunk the database and table name for Hive
  • You tell Splunk the path to the Hive data and what the db paths will look like
  • Splunk will run MUCH faster if your data has partitions

- setting up the provider can be a little bewildering if you have never done it

0 Karma

sabburisplunk
New Member

Thanks a lot. will try this. Just want to make sure, the splunk data here is not archived to Hadoop. We can directly map from Hive to Splunk data model.

0 Karma

burwell
SplunkTrust
SplunkTrust

Yes you associate a virtual index with a Hive table.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...