All Apps and Add-ons

How to create a search using DB connect and using the rising column query to ingest the same?

Splunk4
Explorer

Hi Everyone,

I am trying to ingest the change related data from database using DB connect and using the rising column to ingest the same. I have specified the changerequestID as the rising column. Data has other fields as well such as creationtime,Lastmodifiedtime,Solvedtime etc.If a change is open then the entry in the database for column values such as LastModifiedtime,Solvedtime can be blank so in that case my query is if the these values get updated in the DB after sometime but since the entry before updating has already been ingested in splunk via rising column then will it get ingested in splunk?

Thanks

Labels (2)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The column used as the Rising Column must change every time that row is modified.  If it does not change then Splunk will not read that row and the new data will not be indexed.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...