<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I have a multi-part question around Databricks integration with Splunk? in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/i-have-a-multi-part-question-around-databricks-integration-with/m-p/25850#M18049</link>
    <description>&lt;P&gt;&lt;B&gt;&lt;U&gt;Use Case Background&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;We have an ongoing SecOps project going live here in 4 weeks. We have set up a Splunk to monitor syslogs logs and want to integrate this with Delta. Our forwarder collect the data from remote machines then forwards data to the index in real-time; our indexer processes the incoming stream in real-time and we typically query that data directly in vai the Splunk UI/Search Head.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would like to provide our end users the ability to store historical logs in Delta; then query those directly logs via the Databricks UI/Notebooks/Databricks SQL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;U&gt;Question&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Whether there are any example notebooks or documentation/tips on Splunk integration with Databricks?&lt;/LI&gt;&lt;LI&gt;Whether you can query our logs directly via Databricks?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jun 2021 18:22:53 GMT</pubDate>
    <dc:creator>r_van_niekerk</dc:creator>
    <dc:date>2021-06-07T18:22:53Z</dc:date>
    <item>
      <title>I have a multi-part question around Databricks integration with Splunk?</title>
      <link>https://community.databricks.com/t5/data-engineering/i-have-a-multi-part-question-around-databricks-integration-with/m-p/25850#M18049</link>
      <description>&lt;P&gt;&lt;B&gt;&lt;U&gt;Use Case Background&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;We have an ongoing SecOps project going live here in 4 weeks. We have set up a Splunk to monitor syslogs logs and want to integrate this with Delta. Our forwarder collect the data from remote machines then forwards data to the index in real-time; our indexer processes the incoming stream in real-time and we typically query that data directly in vai the Splunk UI/Search Head.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would like to provide our end users the ability to store historical logs in Delta; then query those directly logs via the Databricks UI/Notebooks/Databricks SQL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;U&gt;Question&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Whether there are any example notebooks or documentation/tips on Splunk integration with Databricks?&lt;/LI&gt;&lt;LI&gt;Whether you can query our logs directly via Databricks?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 18:22:53 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/i-have-a-multi-part-question-around-databricks-integration-with/m-p/25850#M18049</guid>
      <dc:creator>r_van_niekerk</dc:creator>
      <dc:date>2021-06-07T18:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: I have a multi-part question around Databricks integration with Splunk?</title>
      <link>https://community.databricks.com/t5/data-engineering/i-have-a-multi-part-question-around-databricks-integration-with/m-p/25851#M18050</link>
      <description>&lt;P&gt;Yes. Please see the following post for  details - &lt;A href="https://uat-databrickspartner.cs165.force.com/forums/s/question/0D56s00000CxDvqCAF/does-databricks-integrate-with-splunk-what-are-some-ways-to-send-metricslogs-to-splunk" target="test_blank"&gt;https://uat-databrickspartner.cs165.force.com/forums/s/question/0D56s00000CxDvqCAF/does-databricks-integrate-with-splunk-what-are-some-ways-to-send-metricslogs-to-splunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 20:28:28 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/i-have-a-multi-part-question-around-databricks-integration-with/m-p/25851#M18050</guid>
      <dc:creator>aladda</dc:creator>
      <dc:date>2021-06-21T20:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: I have a multi-part question around Databricks integration with Splunk?</title>
      <link>https://community.databricks.com/t5/data-engineering/i-have-a-multi-part-question-around-databricks-integration-with/m-p/25852#M18051</link>
      <description>&lt;P&gt;The&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/5416/" alt="https://splunkbase.splunk.com/app/5416/" target="_blank"&gt;Databricks Add-on for Splunk&lt;/A&gt;&amp;nbsp;built as part of Databricks Labs can be leveraged for Splunk integration&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;It’s a&amp;nbsp;&lt;A href="https://github.com/databrickslabs/splunk-integration/blob/master/docs/markdown/images/functional_architecture.png" alt="https://github.com/databrickslabs/splunk-integration/blob/master/docs/markdown/images/functional_architecture.png" target="_blank"&gt;bi-directional framework&lt;/A&gt;&amp;nbsp;that allows for in-place querying of data in databricks from within Splunk by running queries, notebooks or jobs so you don’t have to move the data and still have access to it from within. Docs are here -&amp;nbsp;&lt;A href="https://github.com/databrickslabs/splunk-integration#Documentation" alt="https://github.com/databrickslabs/splunk-integration#Documentation" target="_blank"&gt;https://github.com/databrickslabs/splunk-integration#Documentation&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 20:28:46 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/i-have-a-multi-part-question-around-databricks-integration-with/m-p/25852#M18051</guid>
      <dc:creator>aladda</dc:creator>
      <dc:date>2021-06-21T20:28:46Z</dc:date>
    </item>
  </channel>
</rss>

