All Apps and Add-ons

Splunk DB Connect 2 Database Output earliest and latest

peter_krammer
Communicator

Hi!

I created a database output with Splunk DB Connect 2, but the app outputted too much data to the DB and it took a long time.
I figured out that the earliest and latest values from the saved search were not used by the db_output script.
So I switched to a non saved search (inline search) in the db output, because there you can select it from the timepicker.
But even than the db output used all time again...
So I looked into the inputs.conf of the app (because it stores its outputs there -.- ) and found out there are no values saved for earliest and latest. Even in the specs in the documentation there is no reference for such values.

How am I supposed to limit my db output to a specific timespan? (eg.: -1d@d to now)

0 Karma

peter_krammer
Communicator

I was able to use the following workaround for the time being.
You can select earliest and latest values in the SPL.
index=test earliest="-1d@d" latest="@d" | ...

But if anybody has a real solution to this I would appreciate it.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...