All Apps and Add-ons

Data is not being shown after configurint DB connect

jesusgalloEMC
Explorer

I created a new DB connect for Splunk it worked good so far using Windows authentication and the Splunk driver
Then I created the Identity and the Connection, all good there.
Afterwards on the DataLab the input is completed, I did the connection in the "Set SQL Query", catalog, schema, table and I execute the SQL and it works perfect, data is being shown.
then when i Click next to "Set properties".

I put the description the Application=Splunk DB Connect
Parameters i leave all by default except for the Execution frequency i put it to run every 5 minutes
metadata i select the Index and SourceType
but when i run the actual search in Splunk it doesnt work it doesnt show anything.
index=main sourcetype=sqldata
and nothing is shown.

Can anyone tell how to troubleshoot?
what frustrates me is that the SQL connection is retrieving results and no errors on the connection, i just dont know why in the Search the index and SourceType set are not showing results.

can any one tell what to look at or Troubleshoot?

Thank you very much!

ansif
Motivator

Check the below few things:

  • Change the time range of your search. (check with All Time)
  • Check whether you have created any custom index for this input.
  • Check which column you have given as time stamp.
0 Karma
Get Updates on the Splunk Community!

This Week's Community Digest - Splunk Community Happenings [9.26.22]

Get the latest news and updates from the Splunk Community here! Upcoming User Group Events! 👏 Check ...

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...