<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to get data from Splunk on daily basis? in Get Started Discussions</title>
    <link>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/57436#M8649</link>
    <description>&lt;P&gt;I am finding the ways to get the data to Databricks from Splunk (similar to other data sources like S3, Kafka, etc.,). I have received a suggestion to use the Databricks add-on to get/put the data from/to Splunk. To pull the data from Databricks to Splunk is easy via setting up this add-on at Splunk side.&lt;/P&gt;&lt;P&gt;But to push the data from Splunk to Databricks, I don't find any documentation in setting up the add-on. If anyone can help me with procedure of setting up this add-on at Databricks side, it will helpful for me to proceed on this. I have got another set of procedure to pull the data from Splunk to Databricks via a github document - &lt;A href="https://github.com/databrickslabs/splunk-integration/blob/master/docs/markdown/Databricks%20-%20Pull%20from%20Splunk.md" target="_self"&gt;here&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The plan is to send the data from Splunk to Databricks on daily basis and build a dashboards on top those data. As it is daily basis data, it could be high volume of data. I would like to know the limitation of sending the data in the respective tools.&lt;/P&gt;&lt;P&gt;I tried to check in Databricks document, but I could not find any information with respect to the communication with Splunk.&lt;/P&gt;&lt;P&gt;Could anyone please help me on finding the best way to send the Splunk data to Databricks?&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jan 2024 10:56:46 GMT</pubDate>
    <dc:creator>Arch_dbxlearner</dc:creator>
    <dc:date>2024-01-16T10:56:46Z</dc:date>
    <item>
      <title>How to get data from Splunk on daily basis?</title>
      <link>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/57436#M8649</link>
      <description>&lt;P&gt;I am finding the ways to get the data to Databricks from Splunk (similar to other data sources like S3, Kafka, etc.,). I have received a suggestion to use the Databricks add-on to get/put the data from/to Splunk. To pull the data from Databricks to Splunk is easy via setting up this add-on at Splunk side.&lt;/P&gt;&lt;P&gt;But to push the data from Splunk to Databricks, I don't find any documentation in setting up the add-on. If anyone can help me with procedure of setting up this add-on at Databricks side, it will helpful for me to proceed on this. I have got another set of procedure to pull the data from Splunk to Databricks via a github document - &lt;A href="https://github.com/databrickslabs/splunk-integration/blob/master/docs/markdown/Databricks%20-%20Pull%20from%20Splunk.md" target="_self"&gt;here&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The plan is to send the data from Splunk to Databricks on daily basis and build a dashboards on top those data. As it is daily basis data, it could be high volume of data. I would like to know the limitation of sending the data in the respective tools.&lt;/P&gt;&lt;P&gt;I tried to check in Databricks document, but I could not find any information with respect to the communication with Splunk.&lt;/P&gt;&lt;P&gt;Could anyone please help me on finding the best way to send the Splunk data to Databricks?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 10:56:46 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/57436#M8649</guid>
      <dc:creator>Arch_dbxlearner</dc:creator>
      <dc:date>2024-01-16T10:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Splunk on daily basis?</title>
      <link>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/57508#M8650</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/97312"&gt;@Arch_dbxlearner&lt;/a&gt;&amp;nbsp; - could you please follow the post for more details.&amp;nbsp; &lt;A href="https://community.databricks.com/t5/data-engineering/does-databricks-integrate-with-splunk-what-are-some-ways-to-send/td-p/22048" target="_blank"&gt;https://community.databricks.com/t5/data-engineering/does-databricks-integrate-with-splunk-what-are-some-ways-to-send/td-p/22048&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 19:40:58 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/57508#M8650</guid>
      <dc:creator>shan_chandra</dc:creator>
      <dc:date>2024-01-16T19:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Splunk on daily basis?</title>
      <link>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/57528#M8651</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/616"&gt;@shan_chandra&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Already I have gone through the post which you have shared above. It is mentioned that the add-on is bi-directional so the communication between Splunk and Databricks can be done.&lt;/P&gt;&lt;P&gt;My requirement is the data to be sent from Splunk to Databricks. I need only one directional activity, where the Splunk data to be used in Databricks and do further activity on Databricks.&lt;/P&gt;&lt;P&gt;So my doubt is where the add-on should be installed. I am going to push the data from Splunk to Databricks. I am aware that it requires HEC but ideally where my Databricks add-on should be placed.&lt;/P&gt;&lt;P&gt;The name says that it is "Databricks add-on for Splunk". I would like to know the process to setup this add-on to push the data only from Splunk to Databricks.&lt;/P&gt;&lt;P&gt;Could you please help me on this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 06:03:48 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/57528#M8651</guid>
      <dc:creator>Arch_dbxlearner</dc:creator>
      <dc:date>2024-01-17T06:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Splunk on daily basis?</title>
      <link>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/57901#M8652</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/97312"&gt;@Arch_dbxlearner&lt;/a&gt;&amp;nbsp;- we can limit access to the user only to read the data from Splunk into Databricks. Please refer below.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/databrickslabs/splunk-integration/blob/master/docs/markdown/Splunk%20DB%20Connect%20guide%20for%20Databricks.md#limit-the-access-of-identities-and-connection-to-particular-users" target="_blank"&gt;https://github.com/databrickslabs/splunk-integration/blob/master/docs/markdown/Splunk%20DB%20Connect%20guide%20for%20Databricks.md#limit-the-access-of-identities-and-connection-to-particular-users&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 17:33:20 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/57901#M8652</guid>
      <dc:creator>shan_chandra</dc:creator>
      <dc:date>2024-01-19T17:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Splunk on daily basis?</title>
      <link>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/72305#M8653</link>
      <description>&lt;P&gt;In my experience with the Splunk add-on,&amp;nbsp; it is typically used to pull Databricks data into Splunk, not to push.&amp;nbsp;&amp;nbsp; If the data sets are small then it could probably push as well, but I think you'd have to write some sort of Splunk map loop to issue INSERT statements against Databricks.&lt;BR /&gt;&lt;BR /&gt;It would probably be more manageable to use this approach,&amp;nbsp; &lt;A href="https://github.com/databrickslabs/splunk-integration/blob/master/docs/markdown/Databricks%20-%20Pull%20from%20Splunk.md" target="_blank"&gt;https://github.com/databrickslabs/splunk-integration/blob/master/docs/markdown/Databricks%20-%20Pull%20from%20Splunk.md&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;This may also provide guidance:&amp;nbsp; &lt;A href="https://registry.terraform.io/modules/databricks/examples/databricks/latest/examples/adb-splunk" target="_blank"&gt;https://registry.terraform.io/modules/databricks/examples/databricks/latest/examples/adb-splunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 10:00:57 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/72305#M8653</guid>
      <dc:creator>hukel</dc:creator>
      <dc:date>2024-06-11T10:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to get data from Splunk on daily basis?</title>
      <link>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/96684#M8654</link>
      <description>&lt;P&gt;Another idea (if you need to do small lookups, not bulk transfer) .... what about using Splunk's splunk-sdk to create a notebook function that hits Splunk via REST API?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 16:53:53 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/how-to-get-data-from-splunk-on-daily-basis/m-p/96684#M8654</guid>
      <dc:creator>hukel</dc:creator>
      <dc:date>2024-10-29T16:53:53Z</dc:date>
    </item>
  </channel>
</rss>

