<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: All DB rows get input as one event in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86597#M7354</link>
    <description>&lt;P&gt;Thanks DAN by checking the output timestamp solved the issue.Can you please explain more on how to create custom source type.I usually leave Sourcetype index and host field value empty.Thanks in advance..&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jan 2013 18:25:21 GMT</pubDate>
    <dc:creator>swathis</dc:creator>
    <dc:date>2013-01-16T18:25:21Z</dc:date>
    <item>
      <title>All DB rows get input as one event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86593#M7350</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I am getting below error when I add data using data inputs from MYSQL to splunk server using DB Connect.In moniter type I choose Dump.Data gets added but all the rows gets added as one event.&lt;BR /&gt;
Here is the error at dbx.log&lt;BR /&gt;
INFO:DumpDatabaseMonitor - Executing database monitor&lt;BR /&gt;
ERROR:DumpDatabaseMonitor - DBMon Error while executing monitor= com.splunk.dbx.monitor.DbmonException: Cancelling subsequent run of oneshot dump monitor.&lt;BR /&gt;
Please advise as how i can solve the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 18:41:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86593#M7350</guid>
      <dc:creator>swathis</dc:creator>
      <dc:date>2013-01-14T18:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: All DB rows get input as one event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86594#M7351</link>
      <description>&lt;P&gt;Have you requested to output the timestamp?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2013 17:40:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86594#M7351</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2013-01-15T17:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: All DB rows get input as one event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86595#M7352</link>
      <description>&lt;P&gt;Results from DB Connect being merged into a single event can be solved by&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Creating a custom sourcetype with specific line breaking/merging rules to create individual events for every line&lt;/LI&gt;
&lt;LI&gt;Enabling the database input to output timestamps (ie. just checking the box "Output timestamp")&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;The error message you're experiencing is actually intended behavior. And as of version 1.0.7 it's not logged anymore. The behavior for a database input of type "dump" without a specific schedule it to index results once and then cancel any subsequent execution.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2013 03:43:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86595#M7352</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2013-01-16T03:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: All DB rows get input as one event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86596#M7353</link>
      <description>&lt;P&gt;I hadn't checked output timestamp once I checked on it...I am getting it correctly.Thanks a ton..&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2013 18:21:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86596#M7353</guid>
      <dc:creator>swathis</dc:creator>
      <dc:date>2013-01-16T18:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: All DB rows get input as one event</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86597#M7354</link>
      <description>&lt;P&gt;Thanks DAN by checking the output timestamp solved the issue.Can you please explain more on how to create custom source type.I usually leave Sourcetype index and host field value empty.Thanks in advance..&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2013 18:25:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/All-DB-rows-get-input-as-one-event/m-p/86597#M7354</guid>
      <dc:creator>swathis</dc:creator>
      <dc:date>2013-01-16T18:25:21Z</dc:date>
    </item>
  </channel>
</rss>

