![]() ![]() Users can then work with database contents without knowing the database credentials stored in the identity.įor more information about setting up and using connections, see Create and manage database connections.Ī database input enables you to retrieve and index data from a database using Splunk Enterprise. As you use Splunk DB Connect, you'll only need to specify the connection to use, and it will use whatever identity you assigned it. When you create a new connection, you specify which identity you want to use with the connection. ![]() While an identity can be used by several connections, each connection can only be assigned a single identity. When you configure a connection, you can specify which roles have read, read-write, or no access to the connection. It consists of the address of your database (the host name), the database's type, and the name of the database. Read-write access means that Splunk Enterprise roles can use and modify the identity.īy default, the admin, sc_admin, and db_connect_admin roles have read/write access to a new identity, the db_connect_user role has read access, and all other roles have no access.įor more information about setting up and using identities, see Create and manage identities.Īfter you create the necessary identities for your database environments, you need to create a connection, which contains the information necessary to connect to a specific database.Read access means that Splunk Enterprise roles can use the identity.When you configure an identity, you can specify the Splunk Enterprise roles that have read, read/write, or no access to the identity. This makes regular password changes easier to support.īe aware that these are database credentials, and are not the same as your Splunk Enterprise credentials. A single identity can be used by many connections, so that service accounts can be easily shared across multiple systems. An identity, which consists of a username and password, defines the database user through which Splunk Enterprise connects to your database. Review Install database drivers for more information and a listing of tested drivers.Ī checklist of steps required for setting up Splunk DB Connect is available at Installation and setup overview for Splunk DB Connect.Īfter you set up Splunk DB Connect, you must create an identity. You must also install a Java Database Connectivity (JDBC) driver so that Splunk Enterprise can communicate with your databases. DB Connect uses a remote procedure call (RPC) server to manage communications with the Java subsystem. For more interactive use, including lookups, install the add-on on a search head.Īll DB Connect instances require Java Runtime Environment (JRE) version 11 or higher in order to enable JDBC. You can use Splunk DB Connect on a heavy forwarder to support continual data gathering or output. To set up Splunk DB Connect, download Splunk DB Connect from Splunkbase, and then follow the instructions in either the single-server or distributed deployment installation topics. Splunk DB Connect enriches and combines unstructured data with structured data, which allows users to cross-reference, augment, and correlate between events in machine logs and external databases. Splunk DB Connect can also send Splunk Enterprise data back for storage in your relational database tables. It enables Splunk Enterprise to connect to and exchange data with databases such as MySQL, Microsoft SQL Server, Informix, DB2, and many others, enriching your Splunk Enterprise data by combining it with data that was previously only available to you directly from those databases. Splunk DB Connect is an add-on that bridges Splunk Enterprise with relational databases through Java Database Connectivity (JDBC).
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |