All Apps and Add-ons

Data is not being shown after configurint DB connect

jesusgalloEMC
Explorer

I created a new DB connect for Splunk it worked good so far using Windows authentication and the Splunk driver
Then I created the Identity and the Connection, all good there.
Afterwards on the DataLab the input is completed, I did the connection in the "Set SQL Query", catalog, schema, table and I execute the SQL and it works perfect, data is being shown.
then when i Click next to "Set properties".

I put the description the Application=Splunk DB Connect
Parameters i leave all by default except for the Execution frequency i put it to run every 5 minutes
metadata i select the Index and SourceType
but when i run the actual search in Splunk it doesnt work it doesnt show anything.
index=main sourcetype=sqldata
and nothing is shown.

Can anyone tell how to troubleshoot?
what frustrates me is that the SQL connection is retrieving results and no errors on the connection, i just dont know why in the Search the index and SourceType set are not showing results.

can any one tell what to look at or Troubleshoot?

Thank you very much!

ansif
Motivator

Check the below few things:

  • Change the time range of your search. (check with All Time)
  • Check whether you have created any custom index for this input.
  • Check which column you have given as time stamp.
0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...