cancel
Showing results for 
Search instead for 
Did you mean: 
Data Engineering
Join discussions on data engineering best practices, architectures, and optimization strategies within the Databricks Community. Exchange insights and solutions with fellow data engineers.
cancel
Showing results for 
Search instead for 
Did you mean: 

I have a multi-part question around Databricks integration with Splunk?

r_van_niekerk
Databricks Employee
Databricks Employee

Use Case Background

We have an ongoing SecOps project going live here in 4 weeks. We have set up a Splunk to monitor syslogs logs and want to integrate this with Delta. Our forwarder collect the data from remote machines then forwards data to the index in real-time; our indexer processes the incoming stream in real-time and we typically query that data directly in vai the Splunk UI/Search Head.

We would like to provide our end users the ability to store historical logs in Delta; then query those directly logs via the Databricks UI/Notebooks/Databricks SQL.

Question

  1. Whether there are any example notebooks or documentation/tips on Splunk integration with Databricks?
  2. Whether you can query our logs directly via Databricks?

Thank you!

2 REPLIES 2

aladda
Databricks Employee
Databricks Employee

aladda
Databricks Employee
Databricks Employee

The Databricks Add-on for Splunk built as part of Databricks Labs can be leveraged for Splunk integration

Connect with Databricks Users in Your Area

Join a Regional User Group to connect with local Databricks users. Events will be happening in your city, and you won’t want to miss the chance to attend and share knowledge.

If there isn’t a group near you, start one and help create a community that brings people together.

Request a New Group