<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117174#M183976</link>
    <description>&lt;P&gt;Thanks a lot Aelliott.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Apr 2014 14:16:28 GMT</pubDate>
    <dc:creator>harshavrath</dc:creator>
    <dc:date>2014-04-10T14:16:28Z</dc:date>
    <item>
      <title>Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117103#M183905</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm trying to get the DB tables as input into Splunk by using Add DB Inputs in Splunk Manager,&lt;BR /&gt;
I'm able to index the Data from my table into Splunk when i don't mention the query(the Splunk creates its own query)&lt;/P&gt;

&lt;P&gt;But when i mention the query such as this &lt;BR /&gt;
SELECT * FROM TABLE_NAME {{WHERE ROWNUM &amp;lt;= 30}} I'm unable to index the data into Splunk.&lt;/P&gt;

&lt;P&gt;This is very important for me as my tables are very large in size so i can't index them completely i need a Where Condition for this&lt;/P&gt;

&lt;P&gt;Any Help is Appreciated,&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 09:56:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117103#M183905</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2014-04-02T09:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117104#M183906</link>
      <description>&lt;P&gt;What do you mean, exactly, when you say you're unable to index the data?  Do you get an error message?  Is there anything in dbx.log?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 11:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117104#M183906</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-04-02T11:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117105#M183907</link>
      <description>&lt;P&gt;2014-04-02 07:44:01.283 dbx2674:ERROR:TailDatabaseMonitor - Configuration Error: [DB_NAME] Invalid query "SELECT * FROM TABLE_NAME {{AND UPDATED_DT &amp;gt; to_date (2001-06-01,'YYYY-MM-DD"T"HH:MI:SS')}}" without proper {{ ... $rising_column$ &amp;gt; ?}} pattern!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:17:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117105#M183907</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2020-09-28T16:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117106#M183908</link>
      <description>&lt;P&gt;2014-04-02 05:21:09.047 dbx6822:ERROR:TailDatabaseMonitor - Configuration Error: [DB_NAME] Invalid query "SELECT * FROM TABLE_NAME {{WHERE ROWNUM &amp;lt;= 10}}" without proper {{ ... $rising_column$ &amp;gt; ?}} pattern!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:17:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117106#M183908</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2020-09-28T16:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117107#M183909</link>
      <description>&lt;P&gt;the errors are in the Query that we specify when we go indexing the DB data into Splunk,IF i don't provide the Query the complete table will be indexed into Splunk.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 12:05:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117107#M183909</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2014-04-02T12:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117108#M183910</link>
      <description>&lt;P&gt;I think you want something like &lt;BR /&gt;
    SELECT * FROM TABLE_NAME WHERE ROWNUM &amp;lt;= 30 {{AND $rising_column$ &amp;gt; ?}}&lt;/P&gt;

&lt;P&gt;Or if you are not doing "Tail"&lt;BR /&gt;
    SELECT * FROM TABLE_NAME WHERE ROWNUM &amp;lt;= 30&lt;/P&gt;

&lt;P&gt;The stuff in the brackets will not be run the first time, so putting {{ where  rownum &amp;lt;= 30 }} will exclude this from the first run.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:17:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117108#M183910</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2020-09-28T16:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117109#M183911</link>
      <description>&lt;P&gt;what I'm i supposed to include in a query if i want to index 1000 rows in a specified time range say Jan 14 to Mar 14.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 13:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117109#M183911</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2014-04-02T13:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117110#M183912</link>
      <description>&lt;P&gt;SELECT * FROM TABLE_NAME WHERE DateField &amp;lt;= '01/01/2014 00:00:00' and DateField &amp;gt;= '03/31/2014 23:59:59'&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 13:52:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117110#M183912</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-04-02T13:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117111#M183913</link>
      <description>&lt;P&gt;If i use dbquery Epoch time is returned i was able to convert it using fieldformat-strftime.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 13:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117111#M183913</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2014-04-02T13:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117112#M183914</link>
      <description>&lt;P&gt;I meant the query to be used for indexing shouldn't we use curly braces for where condition.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 14:08:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117112#M183914</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2014-04-02T14:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117113#M183915</link>
      <description>&lt;P&gt;The stuff in the brackets will not be run the first time the query is run, so if you have curly braces around that, it will grab all your data. the curly braces are meant to hold the {{ $rising_column$ &amp;gt; ?}} pattern&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 14:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117113#M183915</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-04-02T14:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117114#M183916</link>
      <description>&lt;P&gt;Also, You may have to re-create your data input if you are changing the query as it will not re-run the first run again, the clone feature works nicely for this.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 14:16:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117114#M183916</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-04-02T14:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117115#M183917</link>
      <description>&lt;P&gt;I deleted the previous Entry that i had created.I need the Query that I'm supposed to use.As there are some millions of Records in DB i can't index them all in Splunk becoz of 500MB limit,So i want to index some 1000 rows which fall in a said time frame.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 14:25:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117115#M183917</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2014-04-02T14:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117116#M183918</link>
      <description>&lt;P&gt;Right, have you tried any of the queries i have suggested? such as one like &lt;BR /&gt;
     SELECT TOP 1000 * FROM TABLE_NAME WHERE DateField &amp;lt;=  '01/01/2014 00:00:00' and DateField &amp;gt;= '03/31/2014 23:59:59'&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 14:28:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117116#M183918</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-04-02T14:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117117#M183919</link>
      <description>&lt;P&gt;i tried I'm getting an Error as Invalid Month.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 14:31:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117117#M183919</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2014-04-02T14:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117118#M183920</link>
      <description>&lt;P&gt;try this:&lt;BR /&gt;
SELECT TOP 1000 * FROM TABLE_NAME&lt;BR /&gt;
where start_date between to_date('01-JAN-14 00:00:00') &lt;BR /&gt;
       and to_date('31-MAR-14 23:59:59')&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117118#M183920</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2020-09-28T16:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117119#M183921</link>
      <description>&lt;P&gt;Hi,I'm getting this error when i tried the above query&lt;BR /&gt;
command="dbquery", A database error occurred: ORA-01830: date format picture ends before converting entire input string&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 06:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117119#M183921</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2014-04-03T06:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117120#M183922</link>
      <description>&lt;P&gt;Hi,I'm getting results when i tried the below query&lt;/P&gt;

&lt;P&gt;| dbquery DB_NAME limit=100 "SELECT * FROM TABLE_NAME WHERE TRUNC(DATE_FIELD) BETWEEN to_date('04-03 2014','mm/dd/yyyy') AND to_date('04-03 -2014','mm/dd/yyyy') "|fieldformat DATE_FIELD=strftime(DATE_FIELD,"%d-%m-%Y %H: %M: %S")&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:18:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117120#M183922</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2020-09-28T16:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117121#M183923</link>
      <description>&lt;P&gt;But I'm still unable to figure out what is the Select Query that I am supposed to use while Indexing a table into Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 10:25:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117121#M183923</guid>
      <dc:creator>harshavrath</dc:creator>
      <dc:date>2014-04-03T10:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DBConnect Add Databse Inputs Unable to index when we specify the Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117122#M183924</link>
      <description>&lt;P&gt;If you are definining a rising column..&lt;BR /&gt;
SELECT  * FROM TABLE_NAME WHERE TRUNC(DATE_FIELD) BETWEEN to_date('04-03 2014','mm/dd/yyyy') AND to_date('04-03 -2014','mm/dd/yyyy')  {{AND $rising_column$ &amp;gt; ?}}&lt;BR /&gt;
ORDER BY DATE_FIELD ASC&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:18:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-DBConnect-Add-Databse-Inputs-Unable-to-index-when-we/m-p/117122#M183924</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2020-09-28T16:18:29Z</dc:date>
    </item>
  </channel>
</rss>

