<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic This is great news!  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/jdbc-database-integration-with-splunk/m-p/3018878#M1015766</link>
    <description>&lt;P&gt;This is great news!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anyway I can get on the beta release schedule for the App? &amp;nbsp;This is a pressing issue for us. &amp;nbsp;I can reach out to my account team, if that helps.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 May 2017 13:43:43 GMT</pubDate>
    <dc:creator>bo3500001</dc:creator>
    <dc:date>2017-05-01T13:43:43Z</dc:date>
    <item>
      <title>JDBC  Database Integration With Splunk</title>
      <link>https://community.cisco.com/t5/network-security/jdbc-database-integration-with-splunk/m-p/3018876#M1015763</link>
      <description>&lt;P&gt;I am trying to find a way to integrate Splunk and the FireSight Database using the Database access API. &amp;nbsp;Currently, we are using eStreamer for low volume events and syslog alerting for high volume events, such as connection events (as eStreamer chokes on high data volumes). &amp;nbsp;The syslog output does not appear to be configurable, however, the database access API seems to be highly configurable. &amp;nbsp;A few questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Can the database access API be used for high-volume logs across a large deployment (think millions of line of connection events)?&lt;/LI&gt;
&lt;LI&gt;When running the test application "RunQuery" &amp;nbsp;we get sporadic errors that are cryptic. How do we troubleshoot?&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;For example, the query:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;"SELECT first_packet_sec, last_packet_sec, INET6_NTOA(initiator_ipaddr) AS src_ip, INET6_NTOA(responder_ipaddr) AS dest_ip, INET6_NTOA(src_device_ipaddr) as dvc_ip FROM connection_log ORDER BY first_packet_sec DESC, last_packet_sec DESC LIMIT 0, 25;"&lt;/P&gt;
&lt;P&gt;Returns the error: &amp;nbsp;java.sql.SQLException: Table 'rna_flow_stats_1493575800_0' doesn't exist&lt;/P&gt;
&lt;P&gt;But only about 50% of the time. &amp;nbsp;More complex queries return this result all the time. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help is appreciated!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:22:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/jdbc-database-integration-with-splunk/m-p/3018876#M1015763</guid>
      <dc:creator>bo3500001</dc:creator>
      <dc:date>2019-03-12T13:22:45Z</dc:date>
    </item>
    <item>
      <title>The performance limitations</title>
      <link>https://community.cisco.com/t5/network-security/jdbc-database-integration-with-splunk/m-p/3018877#M1015765</link>
      <description>&lt;P&gt;The performance limitations you have experienced with eStreamer are very likely to do with the client - Cisco eStreamer for Splunk TA &amp;amp; App. &amp;nbsp;I'm assuming you are using this:&amp;nbsp;https://splunkbase.splunk.com/app/1629/ &amp;nbsp;It is single threaded.&lt;/P&gt;
&lt;P&gt;The server side of the API on the FMC is capable of handling thousands of events per second depending on the FMC hardware model you use.&lt;/P&gt;
&lt;P&gt;If you are using Firepower version 6.x then you will be able to take advantage of a completely new, built from scratch Splunk TA for eStreamer. &amp;nbsp;The new version is plugin-based, multi-threaded and will provide huge performance advantages. &amp;nbsp;We will post this new TA&amp;amp;App on Splunkbase around June 1st. &amp;nbsp;It will be free but there will also be a paid Cisco TAC support option for customers that want it.&lt;/P&gt;
&lt;P&gt;The Database Access API is not recommended for high volume - continuous event collection. &amp;nbsp;It is very flexible however and so for ad hoc queries of events or especially the Host database its a good way to go.&lt;/P&gt;
&lt;P&gt;I'll ask a more technical person to look at your query. &amp;nbsp;Do you still want to pursue this if the new estreamer - Splunk solution eliminates all the throughput issues?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 13:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/jdbc-database-integration-with-splunk/m-p/3018877#M1015765</guid>
      <dc:creator>dohurd</dc:creator>
      <dc:date>2017-05-01T13:27:00Z</dc:date>
    </item>
    <item>
      <title>This is great news! </title>
      <link>https://community.cisco.com/t5/network-security/jdbc-database-integration-with-splunk/m-p/3018878#M1015766</link>
      <description>&lt;P&gt;This is great news!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anyway I can get on the beta release schedule for the App? &amp;nbsp;This is a pressing issue for us. &amp;nbsp;I can reach out to my account team, if that helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 13:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/jdbc-database-integration-with-splunk/m-p/3018878#M1015766</guid>
      <dc:creator>bo3500001</dc:creator>
      <dc:date>2017-05-01T13:43:43Z</dc:date>
    </item>
    <item>
      <title>Yes.  Please shoot me an</title>
      <link>https://community.cisco.com/t5/network-security/jdbc-database-integration-with-splunk/m-p/3018879#M1015769</link>
      <description>&lt;P&gt;Yes. &amp;nbsp;Please shoot me an email directly. &amp;nbsp;dohurd@cisco.com&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Just need a company name. &amp;nbsp;I'll mail you the package as soon as I have it. &amp;nbsp;Today or tomorrow hopefully.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Doug&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 16:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/jdbc-database-integration-with-splunk/m-p/3018879#M1015769</guid>
      <dc:creator>dohurd</dc:creator>
      <dc:date>2017-05-01T16:17:56Z</dc:date>
    </item>
  </channel>
</rss>

