Hi!
I created a database output with Splunk DB Connect 2, but the app outputted too much data to the DB and it took a long time.
I figured out that the earliest and latest values from the saved search were not used by the db_output script.
So I switched to a non saved search (inline search) in the db output, because there you can select it from the timepicker.
But even than the db output used all time again...
So I looked into the inputs.conf of the app (because it stores its outputs there -.- ) and found out there are no values saved for earliest and latest. Even in the specs in the documentation there is no reference for such values.
How am I supposed to limit my db output to a specific timespan? (eg.: -1d@d to now)
I was able to use the following workaround for the time being.
You can select earliest and latest values in the SPL.
index=test earliest="-1d@d" latest="@d" | ...
But if anybody has a real solution to this I would appreciate it.