All Apps and Add-ons

After updating a query for a Splunk DB Connect input, how do I troubleshoot why it's not showing new events?

kiran331
Builder

Hi all,

I have updated the query the Splunk DB Connect input as I need other fields, but now it's not showing new events. Is there a way to solve it?

Tags (2)
0 Karma

paulbannister
Communicator

Hi,

An older question I know but some people may still be following, can I ask how long you left the new SQL query in place before reverting to the previous working version?

I had a similar issue and reverted after around 20 minutes but discovered no obvious errors, however on a retry of the same query I left it for just over an hour and then data finally appeared, it also might be worth noting to disable the connection prior to changing the query to ensure a clear cut tail value (assuming a rising column is being used)

0 Karma

woodcock
Esteemed Legend
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...