All Apps and Add-ons

After updating a query for a Splunk DB Connect input, how do I troubleshoot why it's not showing new events?

kiran331
Builder

Hi all,

I have updated the query the Splunk DB Connect input as I need other fields, but now it's not showing new events. Is there a way to solve it?

Tags (2)
0 Karma

paulbannister
Communicator

Hi,

An older question I know but some people may still be following, can I ask how long you left the new SQL query in place before reverting to the previous working version?

I had a similar issue and reverted after around 20 minutes but discovered no obvious errors, however on a retry of the same query I left it for just over an hour and then data finally appeared, it also might be worth noting to disable the connection prior to changing the query to ensure a clear cut tail value (assuming a rising column is being used)

0 Karma

woodcock
Esteemed Legend
0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...