All Apps and Add-ons

Rising column in Splunk DB Connect

Explorer

Hi,

I want to ingest data from DBs by creating DB inputs. It has very huge amount of records (around 15million). So I can't use Batch Input. The issue is they don't have any timestamp/unique identifier to put as rising column. So it can't pickup the new records every time. What to do now?

Is there anyway to ingest new records only for every 15 mins?

Thanks,

0 Karma

Splunk Employee
Splunk Employee

I think you have to find an identifier (e.g. rowID, last update date) from the database to be the rising column if you want to use it.

For ingestion new records every 15mins, you could set the interval input.
interval = */15 * * * *

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!