<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk DB connect issue in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705261#M20929</link>
    <description>&lt;P&gt;Is someone can support me on this topic ?&lt;/P&gt;</description>
    <pubDate>Tue, 26 Nov 2024 07:20:37 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2024-11-26T07:20:37Z</dc:date>
    <item>
      <title>Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705242#M20927</link>
      <description>&lt;P&gt;Hello Splunkers!!&lt;BR /&gt;&lt;BR /&gt;I am facing one issue while data getting ingested from DB connect plugin to Splunk. I have mentioned scenarios below. I need your help to fixing it.&lt;/P&gt;&lt;P&gt;In DB connect, I obtain this value at the latest with the STATUS value "FINISHED".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1732594711272.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33584i74F60B6E1BB25882/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1732594711272.png" alt="uagraw01_0-1732594711272.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, when the events come into Splunk, getting the values with the STATUS value "RELEASED" without latest timestamp (UPDATED)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1732594711278.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33585i1FBAB61283A479B6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1732594711278.png" alt="uagraw01_1-1732594711278.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What I am doing so far:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I am using rising column method to get the data into Splunk to avoid duplicate in ingestion.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_2-1732594734816.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33586iD0D73ADF2256BB5B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_2-1732594734816.png" alt="uagraw01_2-1732594734816.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_3-1732594745903.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33587i998AA6564CE5B7AB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_3-1732594745903.png" alt="uagraw01_3-1732594745903.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 04:21:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705242#M20927</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-11-26T04:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705261#M20929</link>
      <description>&lt;P&gt;Is someone can support me on this topic ?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 07:20:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705261#M20929</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-11-26T07:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705264#M20930</link>
      <description>&lt;P&gt;Most probably your DB query initially returned one status which got ingested from the input but later something within your DB changed the status. But since the TASKID is the primary identifier for the ingested records, the same TASKID will not be ingested again. Hence the discrepancy between the DB contents and the indexed data.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 08:16:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705264#M20930</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-26T08:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705266#M20931</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;,&amp;nbsp;&lt;SPAN&gt;If I replace the TASKID column with UPDATED column to rising column method, will it make a difference?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FYI :&amp;nbsp;I also increased the checkpoint value from 1 to 2 and even after the second time STATUS change is RELEASED to FINISHED, that row is not ingested in splunk.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 08:38:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705266#M20931</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-11-26T08:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705281#M20936</link>
      <description>&lt;P&gt;It's not about a field but more about the general layout and variability of data in your DB. Splunk works differently - once you ingest an event, it's immutable whereas the contents of a particular row in DB can change. So regardless of how you decide that one row of your results has already been ingested, it won't be ingested again even if some "secondary" fields change their values.&lt;/P&gt;&lt;P&gt;I don't know your data, I don't know what it represents. If you reconfigure your DB data onboarding process to ingest both states of your DB record (or whatever result set you're getting), you'll have in Splunk two separate&amp;nbsp; partly duplicated events and will have to handle it somehow in search-time.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 11:12:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/705281#M20936</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-26T11:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706132#M20992</link>
      <description>&lt;P&gt;My database contains two types of events, and I want to ensure that only the &lt;STRONG&gt;latest row&lt;/STRONG&gt; for each unique TASKID is ingested into Splunk with the following requirements:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Latest Status&lt;/STRONG&gt;: Only the most recent status for each TASKID should be captured, determined by the UPDATED timestamp field.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Latest Date&lt;/STRONG&gt;: The row with the most recent UPDATED timestamp for each TASKID should be ingested into Splunk.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Single Count&lt;/STRONG&gt;: Each TASKID should appear only once in Splunk, with no duplicates or older rows included.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;BR /&gt;Please help me achieve this requirement. Currently method I am using is "Rising column update" method. But still splunk is not ingesting a row with the latest status.&lt;BR /&gt;&lt;BR /&gt;I am using below query in SQL input under DB connect.&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;SELECT *&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;FROM "DB"."KSF_OVERVIEW"&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;WHERE TASKIDUPDATED &amp;gt; ?&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;ORDER BY TASKIDUPDATED ASC&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;Below are the sample events from the database.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;=====Status "FINISHED"&lt;/P&gt;&lt;P&gt;2024-12-06 11:50:22.984, TASKID="11933815411", TASKLABEL="11933815411", TASKIDUPDATED="11933815411 2024/12/05 19:40:47", TASKTYPEKEY="PACKGROUP", CREATED="2024-12-05 14:18:18", UPDATED="2024-12-05 19:40:47", STATUSTEXTKEY="Dynamic|TaskStatus.key{FINISHED}.textKey", CONTROLLERSTATUSTEXTKEY="Dynamic|TaskControllerStatus.taskTypeKey{PACKGROUP},key{EXECUTED}.textKey", STATUS="FINISHED", CONTROLLERSTATUS="EXECUTED", REQUIREDFINISHTIME="2024-12-06 00:00:00", STATION="PAL/Pal02", REQUIRESCUBING="0", REQUIRESQUALITYCONTROL="0", PICKINGSUBTASKCOUNT="40", TASKTYPETEXTKEY="Dynamic|TaskType.Key{PACKGROUP}.textKey", OPERATOR="1", MARSHALLINGTIME="2024-12-06 06:30:00", TSU="340447278164799274", FMBARCODE="WMC000000000341785", TSUTYPE="KKP", TOURNUMBER="2820007682", TYPE="DELIVERY", DELIVERYNUMBER="17620759", DELIVERYORDERNUMBER="3372948211", SVSSTATUS="DE_FINISHED", STORENUMBER="0000002590", STACK="11933816382", POSITION="Bottom", LCTRAINID="11935892717", MARSHALLINGAREA="WAB"&lt;/P&gt;&lt;P&gt;=====Status "RELEASED"&lt;/P&gt;&lt;P&gt;2024-12-05 14:20:13.290, TASKID="11933815411", TASKLABEL="11933815411", TASKIDUPDATED="11933815411 2024/12/05 14:18:20", TASKTYPEKEY="PACKGROUP", CREATED="2024-12-05 14:18:18", UPDATED="2024-12-05 14:18:20", STATUSTEXTKEY="Dynamic|TaskStatus.key{RELEASED}.textKey", CONTROLLERSTATUSTEXTKEY="Dynamic|TaskControllerStatus.taskTypeKey{PACKGROUP},key{CREATED}.textKey", STATUS="RELEASED", CONTROLLERSTATUS="CREATED", REQUIREDFINISHTIME="2024-12-06 00:00:00", REQUIRESCUBING="0", REQUIRESQUALITYCONTROL="0", PICKINGSUBTASKCOUNT="40", TASKTYPETEXTKEY="Dynamic|TaskType.Key{PACKGROUP}.textKey", OPERATOR="1", MARSHALLINGTIME="2024-12-06 06:30:00", TSUTYPE="KKP", TOURNUMBER="2820007682", TYPE="DELIVERY", DELIVERYNUMBER="17620759", DELIVERYORDERNUMBER="3372948211", SVSSTATUS="DE_CREATED", STORENUMBER="0000002590", STACK="11933816382", POSITION="Bottom", MARSHALLINGAREA="WAB"&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 11:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706132#M20992</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-12-06T11:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706135#M20993</link>
      <description>&lt;P&gt;Again - there is no way to update an existing event within Splunk. So you can't have only the latest status. As simple as that.&lt;/P&gt;&lt;P&gt;You can try to walk around that by maybe ingesting the state periodically and hold the state in a lookup or something similar but this approach doesn't scale well.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 11:29:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706135#M20993</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-06T11:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706259#M21006</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;I am using field name "&lt;SPAN&gt;TASKIDUPDATED" which is the combination of TASKID and UPDATED column and it is always dynamic in nature.&amp;nbsp;I have given this field in the rising column and this field is changing in every run. Even after this, duplicate data is being ingested.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2024 14:32:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706259#M21006</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-12-08T14:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706284#M21012</link>
      <description>&lt;P&gt;Whay do you mean by "duplicate" in this context? Two different values for the same TASKID? That's expected.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2024 20:34:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706284#M21012</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-08T20:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706301#M21013</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;I mean to say.&amp;nbsp;The value of the TASKIDUPDATED field is always unique value&amp;nbsp;after applying checkpoint value event should be ingested only once and not multiple times.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Below is the setting I am currently using for db connect.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;connection = VIn
disabled = 0
index = group_data
index_time_mode = current
interval = */10 * * * *
max_rows = 0
mode = rising
query = SELECT * FROM "WMCDB"."KLDGSF_ROUPOVERVIEW"\
WHERE TASKIDUPDATED &amp;lt; ?\
ORDER BY TASKIDUPDATED DESC
query_timeout = 30
sourcetype = overview_packgroup
tail_rising_column_init_ckpt_value = {"value":null,"columnType":null}
tail_rising_column_name = TASKIDUPDATED
tail_rising_column_number = 3
input_timestamp_column_number = 10
input_timestamp_format =&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 09 Dec 2024 15:06:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706301#M21013</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-12-09T15:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706312#M21016</link>
      <description>&lt;P&gt;OK. Let's back up a little.&lt;/P&gt;&lt;P&gt;You have a record with&lt;/P&gt;&lt;P&gt;TASKID=1&lt;BR /&gt;UPDATED=1&lt;BR /&gt;VALUE="A"&lt;BR /&gt;TASKIDUPDATED="1-1"&lt;/P&gt;&lt;P&gt;You update the VALUE and the UPDATED field and the TASKIDUPDATED field is updated as well so you have&lt;/P&gt;&lt;P&gt;TASKID=1&lt;BR /&gt;UPDATED=2&lt;BR /&gt;VALUE="B"&lt;BR /&gt;TASKIDUPDATED="1-2"&lt;/P&gt;&lt;P&gt;From Splunk's point of view it's a completely different entity since your TASKIDUPDATED changed (even though from your database point of view it can still be the same record). Splunk doesn't care about state of your database. It just fetches some results from database query.&lt;/P&gt;&lt;P&gt;You can - to some extent - compare it to the file monitor input. If you have a log file which Splunk is monitoring and you change some sequence of bytes in the middle of that file to a different sequence, Splunk has no way of knowing that something changed - the event which had been read from that position and ingested into Splunk stays the same. (of course there can be issues when Splunk notices file that file has been truncated and decides to reread whole file or just stops reading from the file because it decides it reached the end of the file but these are beside the main point).&lt;/P&gt;&lt;P&gt;BTW, remember that setting a non-numeric column to bee your rising column may yield unpredictible results due to quirkness of sorting.&lt;/P&gt;&lt;P&gt;EDIT warning - previous version of this reply mistakenly used the same field name twice.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 11:38:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-connect-issue/m-p/706312#M21016</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-09T11:38:10Z</dc:date>
    </item>
  </channel>
</rss>

