All Apps and Add-ons

Data is not being shown after configurint DB connect

jesusgalloEMC
Explorer

I created a new DB connect for Splunk it worked good so far using Windows authentication and the Splunk driver
Then I created the Identity and the Connection, all good there.
Afterwards on the DataLab the input is completed, I did the connection in the "Set SQL Query", catalog, schema, table and I execute the SQL and it works perfect, data is being shown.
then when i Click next to "Set properties".

I put the description the Application=Splunk DB Connect
Parameters i leave all by default except for the Execution frequency i put it to run every 5 minutes
metadata i select the Index and SourceType
but when i run the actual search in Splunk it doesnt work it doesnt show anything.
index=main sourcetype=sqldata
and nothing is shown.

Can anyone tell how to troubleshoot?
what frustrates me is that the SQL connection is retrieving results and no errors on the connection, i just dont know why in the Search the index and SourceType set are not showing results.

can any one tell what to look at or Troubleshoot?

Thank you very much!

ansif
Motivator

Check the below few things:

  • Change the time range of your search. (check with All Time)
  • Check whether you have created any custom index for this input.
  • Check which column you have given as time stamp.
0 Karma
Get Updates on the Splunk Community!

Testing out the OpenTelemetry Collector With raw Data

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

New Cloud Intrusion Detection System Add-on for Splunk

In July 2022 Splunk released the Cloud IDS add-on which expanded Splunk capabilities in security and data ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...