<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DB Connect Rising Column type in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94508#M22713</link>
    <description>&lt;P&gt;The string representation of time should be comparable in the right way. This should work.&lt;/P&gt;

&lt;P&gt;One thing you will have to change is your output timestamp formatting, so that the events make it into Splunk in the right way. In your stanza in inputs.conf:&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
output.timestamp = 1&lt;BR /&gt;
output.timestamp.column = USE_START_DTIME&lt;BR /&gt;
output.timestamp.parse.format = yyyyMMddHHmmss&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:10:57 GMT</pubDate>
    <dc:creator>Dan</dc:creator>
    <dc:date>2020-09-28T13:10:57Z</dc:date>
    <item>
      <title>DB Connect Rising Column type</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94505#M22710</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have some problem.&lt;BR /&gt;
My database table rising_column type is varchar2.&lt;BR /&gt;
So tail monitoring is not working.&lt;BR /&gt;
We cannot change column type and we have no number, date type of rising column.&lt;BR /&gt;
How can I do ?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2013 08:54:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94505#M22710</guid>
      <dc:creator>gilla</dc:creator>
      <dc:date>2013-01-22T08:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Rising Column type</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94506#M22711</link>
      <description>&lt;P&gt;Rising column can be any column type that is comparable. Technically, varchar2 is comparable (see &lt;A href="http://docs.oracle.com/cd/B14117_01/server.101/b10759/sql_elements002.htm"&gt;here&lt;/A&gt; for details from Oracle). Although tail monitoring will function, it may not give you desired results.&lt;/P&gt;

&lt;P&gt;It could be that your table just isn't a good candidate for tail input. You can consider the dump input instead. Or, you can add an auto-incrementing field to the table, which won't require developers to write any extra SQL for every INSERT (see &lt;A href="http://situsnya.wordpress.com/2008/09/02/how-to-create-auto-increment-columns-in-oracle/"&gt;here&lt;/A&gt; again for Oracle).&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 22:09:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94506#M22711</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2013-01-23T22:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Rising Column type</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94507#M22712</link>
      <description>&lt;P&gt;Thank you for your answer.&lt;BR /&gt;
But my customer do not want to modify database table.&lt;BR /&gt;
And table is very large size and quickly increasing, so dump input is not available.&lt;BR /&gt;
Column name is USE_START_DTIME, type is varchar2(14).&lt;BR /&gt;
and data is 20130123102132. It is timestamp, but DB Connect App recognize string format. State.xml is below :&lt;BR /&gt;
&lt;LIST&gt;&lt;BR /&gt;
   &lt;VALUE key="latest.USE_START_DTIME"&gt;&lt;BR /&gt;
      &lt;VALUE class="string"&gt;20130121182208&lt;/VALUE&gt;&lt;BR /&gt;
   &lt;/VALUE&gt;&lt;BR /&gt;
&lt;/LIST&gt;&lt;BR /&gt;
And value key is not update. It means tail function is not working.&lt;/P&gt;

&lt;P&gt;Anyway, thank you again, Dan!!!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:10:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94507#M22712</guid>
      <dc:creator>gilla</dc:creator>
      <dc:date>2020-09-28T13:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Rising Column type</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94508#M22713</link>
      <description>&lt;P&gt;The string representation of time should be comparable in the right way. This should work.&lt;/P&gt;

&lt;P&gt;One thing you will have to change is your output timestamp formatting, so that the events make it into Splunk in the right way. In your stanza in inputs.conf:&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
output.timestamp = 1&lt;BR /&gt;
output.timestamp.column = USE_START_DTIME&lt;BR /&gt;
output.timestamp.parse.format = yyyyMMddHHmmss&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94508#M22713</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2020-09-28T13:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Rising Column type</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94509#M22714</link>
      <description>&lt;P&gt;I'm really sorry about this situation.&lt;BR /&gt;
Yes... DBX app is working correctly.&lt;BR /&gt;
I have simple mistake of configuration.&lt;BR /&gt;
And now everything is OK!!!&lt;BR /&gt;
DBX App is very very nice App!!!&lt;BR /&gt;
Thank you very much, Dan!!!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 06:36:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/DB-Connect-Rising-Column-type/m-p/94509#M22714</guid>
      <dc:creator>gilla</dc:creator>
      <dc:date>2013-01-28T06:36:42Z</dc:date>
    </item>
  </channel>
</rss>

