All Apps and Add-ons

DB Connect input no longer refreshing index with data from database

splunknoob408
Explorer

Please pardon any incorrect terminology here as I try to explain the problem I am having. 🙂

I have a database that contains log information and I created a "rising" input in DB Connect with a 60 second refresh. The rising column is set to my timestamp field.

I was under the impression that this means every 60 seconds, splunk will hit my database and pull in all of the latest records since the last fetch. It also seemed to work fine for a day or so. However, today I noticed my dashboard hadn't updated, and the last data pulled from the DB was on 12/15.

I have no idea why it's not refreshing the data, so I am hoping that someone here can shed some light on possible misconfiguration on my part. Thank you!

0 Karma
1 Solution

splunknoob408
Explorer

I realized that the problem was with my search. I had forgotten that when I started to learn about indexes, I changed my approach to create an index for aggregating my shipping data from multiple database tables. It was indexing that all along, and my old source (for one reason or another) stopped updating. I'm not sure why that would happen, but once I replaced the source with "index=shipping" in my search, it ran as expected.

View solution in original post

0 Karma

splunknoob408
Explorer

I realized that the problem was with my search. I had forgotten that when I started to learn about indexes, I changed my approach to create an index for aggregating my shipping data from multiple database tables. It was indexing that all along, and my old source (for one reason or another) stopped updating. I'm not sure why that would happen, but once I replaced the source with "index=shipping" in my search, it ran as expected.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...