I got an issue with Splunk DB Connect app.
After indexing data from my Oracle DB, Splunk doesn't recognize field-value pairs
I got an event like that:
06/02/2018, Name=myname, Date_of_birth=24/10/1987
In the interesting fields I don't find the field name and Date_of_birth but only index, linecount and punct.
How can I solve my problem?
Can you please double check whether are you getting data in double quote or not ? Like this
06/02/2018, Name="myname", Date_of_birth="24/10/1987"
Because when I tried to fetch data from Oracle database all fields with value coming in double quotes as mentioned above.