<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Splunk DB Connect 3 days behind indexing ePO data? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366701#M44307</link>
    <description>&lt;P&gt;hello again, no there are no error messages in the dbx.log &lt;/P&gt;

&lt;P&gt;======================================================================================&lt;BR /&gt;
2017-03-20 11:45:34.916 dbx4196:INFO:TailDatabaseMonitor - Database monitor=[dbmon-tail://epo_b-edc/epo_b-edc_5] finished with status=true resultCount=10000 in duration=886266 ms&lt;BR /&gt;
2017-03-20 11:45:34.916 dbx4196:INFO:ExecutionContext - Execution finished in duration=886266 ms&lt;/P&gt;

&lt;H1&gt;2017-03-20 11:45:34.916 monsch1:INFO:Scheduler - Execution of input=[dbmon-tail://epo_b-edc/epo_b-edc_5] finished in duration=886266 ms with resultCount=10000 success=true continueMonitoring=true&lt;/H1&gt;

&lt;P&gt;what is happening is that the logs are coming, but they are three days behind, so today is the 20th, we can see logs from up to the 17th only. Tomorrow the 21st we will see logs up to the 18th.  &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 13:18:40 GMT</pubDate>
    <dc:creator>bluemarvel</dc:creator>
    <dc:date>2020-09-29T13:18:40Z</dc:date>
    <item>
      <title>Why is Splunk DB Connect 3 days behind indexing ePO data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366697#M44303</link>
      <description>&lt;P&gt;We are seeing logs in Splunk  but there are lagging; meaning they are always 3 days behind. I.E we can only see logs from the 14th and prior. Is there a some time format or other configuration that needs to be changed? &lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2017 20:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366697#M44303</guid>
      <dc:creator>bluemarvel</dc:creator>
      <dc:date>2017-03-17T20:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk DB Connect 3 days behind indexing ePO data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366698#M44304</link>
      <description>&lt;P&gt;As per the documentation &lt;A href="https://docs.splunk.com/Documentation/DBX/3.0.1/DeployDBX/Createandmanagedatabaseinputs"&gt;https://docs.splunk.com/Documentation/DBX/3.0.1/DeployDBX/Createandmanagedatabaseinputs&lt;/A&gt; is it possible your  max rows to retrieve is too small?&lt;BR /&gt;
There is also a query timeout of 30 seconds within the db_inputs.conf you could possibly be hitting &lt;A href="https://docs.splunk.com/Documentation/DBX/3.0.1/DeployDBX/dbinputs"&gt;https://docs.splunk.com/Documentation/DBX/3.0.1/DeployDBX/dbinputs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2017 22:28:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366698#M44304</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-03-17T22:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk DB Connect 3 days behind indexing ePO data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366699#M44305</link>
      <description>&lt;P&gt;thank you for the advice, much appreciated. Still having and issue after I changed the max_rows value to all, (max_row = all) which is the default from what i have read. &amp;gt;&amp;gt;{/splunk/etc/apps/dbx/local/inputs.conf}&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366699#M44305</guid>
      <dc:creator>bluemarvel</dc:creator>
      <dc:date>2020-09-29T14:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk DB Connect 3 days behind indexing ePO data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366700#M44306</link>
      <description>&lt;P&gt;Do the DB Connect logs in /opt/splunk/var/log/splunk/splunk_app_db_connect_* give you any hints?&lt;BR /&gt;
You can also find them in the internal index, they might tell you waht is happening...&lt;/P&gt;

&lt;P&gt;Furthermore, are you sure the records are old ? i.e. do you have an issue parsing the timestamps/using the wrong time column or similar ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:18:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366700#M44306</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-09-29T13:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk DB Connect 3 days behind indexing ePO data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366701#M44307</link>
      <description>&lt;P&gt;hello again, no there are no error messages in the dbx.log &lt;/P&gt;

&lt;P&gt;======================================================================================&lt;BR /&gt;
2017-03-20 11:45:34.916 dbx4196:INFO:TailDatabaseMonitor - Database monitor=[dbmon-tail://epo_b-edc/epo_b-edc_5] finished with status=true resultCount=10000 in duration=886266 ms&lt;BR /&gt;
2017-03-20 11:45:34.916 dbx4196:INFO:ExecutionContext - Execution finished in duration=886266 ms&lt;/P&gt;

&lt;H1&gt;2017-03-20 11:45:34.916 monsch1:INFO:Scheduler - Execution of input=[dbmon-tail://epo_b-edc/epo_b-edc_5] finished in duration=886266 ms with resultCount=10000 success=true continueMonitoring=true&lt;/H1&gt;

&lt;P&gt;what is happening is that the logs are coming, but they are three days behind, so today is the 20th, we can see logs from up to the 17th only. Tomorrow the 21st we will see logs up to the 18th.  &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366701#M44307</guid>
      <dc:creator>bluemarvel</dc:creator>
      <dc:date>2020-09-29T13:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk DB Connect 3 days behind indexing ePO data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366702#M44308</link>
      <description>&lt;P&gt;The logs indicate:&lt;BR /&gt;
resultCount=10000 &lt;/P&gt;

&lt;P&gt;Did you try increasing this number to see if you just need more data per-request? Do you have more than 10K of rows per day? Or alternatively you can set the query to run more often/more times per day?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 23:20:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366702#M44308</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-03-20T23:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk DB Connect 3 days behind indexing ePO data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366703#M44309</link>
      <description>&lt;P&gt;is this also in the local.con file because I am not seeing it. &lt;BR /&gt;
the other config change that I made  proved not have worked. &lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2017 18:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366703#M44309</guid>
      <dc:creator>bluemarvel</dc:creator>
      <dc:date>2017-03-21T18:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk DB Connect 3 days behind indexing ePO data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366704#M44310</link>
      <description>&lt;P&gt;So we decided to move on to DB Connect 2 for our EPO events, however I am seeing two different database drivers for this, whicn is the right one? &lt;/P&gt;

&lt;P&gt;sqljdbc4.jar and postgresql-9.4.1212.jre6.jar &lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 21:38:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-is-Splunk-DB-Connect-3-days-behind-indexing-ePO-data/m-p/366704#M44310</guid>
      <dc:creator>bluemarvel</dc:creator>
      <dc:date>2017-03-27T21:38:52Z</dc:date>
    </item>
  </channel>
</rss>

