All Apps and Add-ons

DB Connect input no longer refreshing index with data from database

splunknoob408
Explorer

Please pardon any incorrect terminology here as I try to explain the problem I am having. 🙂

I have a database that contains log information and I created a "rising" input in DB Connect with a 60 second refresh. The rising column is set to my timestamp field.

I was under the impression that this means every 60 seconds, splunk will hit my database and pull in all of the latest records since the last fetch. It also seemed to work fine for a day or so. However, today I noticed my dashboard hadn't updated, and the last data pulled from the DB was on 12/15.

I have no idea why it's not refreshing the data, so I am hoping that someone here can shed some light on possible misconfiguration on my part. Thank you!

0 Karma
1 Solution

splunknoob408
Explorer

I realized that the problem was with my search. I had forgotten that when I started to learn about indexes, I changed my approach to create an index for aggregating my shipping data from multiple database tables. It was indexing that all along, and my old source (for one reason or another) stopped updating. I'm not sure why that would happen, but once I replaced the source with "index=shipping" in my search, it ran as expected.

View solution in original post

0 Karma

splunknoob408
Explorer

I realized that the problem was with my search. I had forgotten that when I started to learn about indexes, I changed my approach to create an index for aggregating my shipping data from multiple database tables. It was indexing that all along, and my old source (for one reason or another) stopped updating. I'm not sure why that would happen, but once I replaced the source with "index=shipping" in my search, it ran as expected.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...