All Apps and Add-ons

Rising column in Splunk DB Connect

uhkc777
Explorer

Hi,

I want to ingest data from DBs by creating DB inputs. It has very huge amount of records (around 15million). So I can't use Batch Input. The issue is they don't have any timestamp/unique identifier to put as rising column. So it can't pickup the new records every time. What to do now?

Is there anyway to ingest new records only for every 15 mins?

Thanks,

0 Karma

tlam_splunk
Splunk Employee
Splunk Employee

I think you have to find an identifier (e.g. rowID, last update date) from the database to be the rising column if you want to use it.

For ingestion new records every 15mins, you could set the interval input.
interval = */15 * * * *

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...