All Apps and Add-ons

In the Splunk DB Connect app, after indexing data from my Oracle DB, Why doesn't Splunk recognize field-value pairs?

Explorer

Hello there,
I got an issue with Splunk DB Connect app.
After indexing data from my Oracle DB, Splunk doesn't recognize field-value pairs

I got an event like that:

06/02/2018, Name=myname, Date_of_birth=24/10/1987

In the interesting fields I don't find the field name and Date_of_birth but only index, linecount and punct.

How can I solve my problem?

Tnx

0 Karma
1 Solution

SplunkTrust
SplunkTrust

As this data is not in CSV format, can you please change sourcetype to some custom sourcetype??

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

As this data is not in CSV format, can you please change sourcetype to some custom sourcetype??

View solution in original post

0 Karma

Explorer

i solved the issue using a custom sourcetype.

Tnx so much for the help 🙂

0 Karma

SplunkTrust
SplunkTrust

I have converted my comment to answer so you can accept/upvote it.

0 Karma

SplunkTrust
SplunkTrust

Are you running your search in fastmode ? Try to change it to Smartmode or Verbosemode.

0 Karma

Explorer

Hi,
the search is running in verbose mode.

0 Karma

SplunkTrust
SplunkTrust

Can you please double check whether are you getting data in double quote or not ? Like this 06/02/2018, Name="myname", Date_of_birth="24/10/1987"

Because when I tried to fetch data from Oracle database all fields with value coming in double quotes as mentioned above.

0 Karma

Explorer

Hi,
data are getting in with double quote as mentioned 🙂

0 Karma

SplunkTrust
SplunkTrust

What sourcetype are you using for this data ? Any props.conf or transforms.conf present for that sourcetype ?

0 Karma

Explorer

i'm using CSV sourcetype

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!