I'm pretty new to Splunk so am configuring this with the help of the guides. I have configured the Splunk DB Connect 2 app to query a table in my MS SQL server.
Everything shows a valid connection when configuring the data input and the query returns data for me to configure it with. I have a rising column set and when checking the rpc.log, I can see the query running. In here, the query says
RisingColumnName > ? ORDER BY RisingColumnName ASC
of course replacing
RisingColumnName with the actual column - I'm not sure if the
? is just something to do with Splunk or if this should in fact be the ID for the rising column?
Not sure what to look at now. I just can't get any of my data from SQL into SplunK!