Hi all,
I have updated the query the Splunk DB Connect input as I need other fields, but now it's not showing new events. Is there a way to solve it?
Hi,
An older question I know but some people may still be following, can I ask how long you left the new SQL query in place before reverting to the previous working version?
I had a similar issue and reverted after around 20 minutes but discovered no obvious errors, however on a retry of the same query I left it for just over an hour and then data finally appeared, it also might be worth noting to disable the connection prior to changing the query to ensure a clear cut tail value (assuming a rising column is being used)
Go here (especially the logs section):
http://docs.splunk.com/Documentation/DBX/2.2.0/DeployDBX/Troubleshooting