Article Details

Splunk and Snowflake bring federated search without the data-moving hangover - iTWire

Retrieved on: 2025-10-05 11:29:36

Tags for this article:

Click the tags to see associated articles and topics

Splunk and Snowflake bring federated search without the data-moving hangover - iTWire. View article details on hiswai:

Summary

Carl Perry from Snowflake discusses the company's new federated search integration with Splunk, announced at Splunk .conf 25 in Boston.

This collaboration enables organizations to search across both Splunk machine data and Snowflake business data simultaneously without centralizing or moving information. The integration allows teams to correlate operational incidents with business impacts through unified searches, maintaining data in its original location while providing a single interface for SecOps, ITOps, and engineering teams.

  • Query Snowflake directly from Splunk using familiar SPL-like syntax while joining tables with Splunk indexes
  • Built on open table formats, particularly Apache Iceberg, ensuring vendor-neutral flexibility and avoiding data lock-in
  • Currently in design phase with plans to extend federated search capabilities to other platforms like Databricks and BigQuery
  • Reduces costs and complexity by eliminating data movement while enabling cross-platform insights for better decision-making

Article found on: itwire.com

View Original Article

This article is found inside other hiswai user's workspaces. To start your own collection, sign up for free.

Sign Up
Book a Demo