All Apps and Add-ons

Splunk DB Connect: How to create new DB Inputs?

aniello_cerrato
Path Finder

Hi,

I am trying to create a new DB input on Splunk DB Connect. I have to schedule the search every one hour (that gets the data changed in the last hour) but when I create the input the search, it returns zero records and I can't proceed to create db inputs.

Do you have a solution to create db inputs if the relative search returns no records?

Thanks,
Aniello

0 Karma

earlhelms
Path Finder

I have had the same issue countless times. The only work around that I've came up with is to modify the search to add a record. Typically when modifying an existing input, I roll back the rising column by 1 and add the last record again as a duplicate entry.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...