Splunk Hadoop Connect
provides bi-directional integration to move data between the Splunk
platform and Hadoop. Deploy the Splunk platform for real-time
collection, indexing, analysis, and visualizations and then forward
events to Hadoop for archiving and additional batch analytics. You can
also import data that is already stored in Hadoop.
With Splunk Hadoop Connect, you can:
Deliver
events in their raw form or preprocessed from the Splunk platform to
Hadoop Distributed File System (HDFS) or a mounted file system.
Explore HDFS and your mounted file system.
Import
data from HDFS into the Splunk platform at search or index time, if you
are using the Splunk platform version 5.0 or later.