All Apps and Add-ons

After updating a query for a Splunk DB Connect input, how do I troubleshoot why it's not showing new events?


Hi all,

I have updated the query the Splunk DB Connect input as I need other fields, but now it's not showing new events. Is there a way to solve it?

Tags (2)
0 Karma



An older question I know but some people may still be following, can I ask how long you left the new SQL query in place before reverting to the previous working version?

I had a similar issue and reverted after around 20 minutes but discovered no obvious errors, however on a retry of the same query I left it for just over an hour and then data finally appeared, it also might be worth noting to disable the connection prior to changing the query to ensure a clear cut tail value (assuming a rising column is being used)

0 Karma

Esteemed Legend
0 Karma
Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...