All Apps and Add-ons

Splunk DB Connect: Input and temp tables

kbcall
Explorer

We have a very complex query that creates temp tables and declares variable. We can execute the SQL in Splunk and it returns the correct results but it will not allow us to save the SQL. Is there any way to work around using temp tables with DB connect inputs?

0 Karma
1 Solution

tmuth_splunk
Splunk Employee
Splunk Employee

It would help to know what database. If it’s one of the DBs that DBX supports for stored procedures, you could wrap all of your logic in a stored proc, then call that from DBX.

View solution in original post

0 Karma

tmuth_splunk
Splunk Employee
Splunk Employee

It would help to know what database. If it’s one of the DBs that DBX supports for stored procedures, you could wrap all of your logic in a stored proc, then call that from DBX.

0 Karma

kbcall
Explorer

MS SQL 2012 is our Database. In the previous version we tried a simple exec sp_who but DBConnect would not accept that as an input. Does DBConnect now support running stored procedures as inputs?

0 Karma

sochsenbein
Communicator

@tmuth We are still having this issue where the stored procedures are returning no results when they use temp tables. We are running Splunk version 7.0.0 and DB 3.0. Any advice?

0 Karma

kelseycasco
New Member

I am also having this problem.. the db_connect_server log says "A processing error "Invalid object name"

0 Karma

tmuth_splunk
Splunk Employee
Splunk Employee

Yes, DBX 3.x supports stored procedures. I’m mobile or I would send a direct link to the doc for it.

0 Karma

kbcall
Explorer

Thanks. I retired a simple stored procedure and I was able to save it as an input. We will experiment more with a more completed stored procedure.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...