All Apps and Add-ons

Splunk DB Connect 2: Why are we getting no results in pivot when using a dbxquery query?

pieterms
New Member

We use the following database query in search mode.

|dbxquery query="SELECT%20*%20FROM%20%60app%60.%60order%60" connection="sqldb" maxrows=100 

When we want to make a pivot for these results, the "count of event object" stays on 0. When I press on the "count of event object" link, the following search qeury will be displayed on screen in search mode again.

(dbxquery query="SELECT%20*%20FROM%20%60app%60.%60order%60" connection="sqldb")  

The pipe character is disappeared so the query doesn't work anymore. How do I solve this problem so we can make pivot visualizations for these queries?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

that data will have to be indexed to be used with pivot.

0 Karma

pieterms
New Member

How can I index this data?

I think this data already indexed via the Splunk DB Connect 2 - DB Input. The meta data is set in this plugin.

0 Karma

karthikeyan_mac
New Member

I have created the DB Input. Is there another way to index the data?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...