All Apps and Add-ons

Splunk DB Connect Step 4 Warning

Mcap08
New Member

Hello,

 

Current SQL Query:

SELECT *
FROM "vxex"."dbaex"."Example_Log_View"
WHERE [Event Time] > ?
ORDER BY [Event Time] ASC

I am having some issues with log duplication on one of my inputs... The SQL Query I have executes, but It gives me a warning on Step 4 within my Rising Input Option:

Mcap08_0-1692972229609.png

 

I am not too versed in Splunk DB Connect.. I believe it may be the space in the Event Time Column name.. But put [] around it to mitigate that.. As it still runs to step 5.

 

Mcap08_1-1692972875601.png

 

What I do see is the Checkpoint Value of 01/01/1970... And here are some Examples of the Event Time that comes through from the SQL Query:

2023-04-20 10:02:30.87

2023-04-20 10:03:23.783

 

Any thoughts on how to troubleshoot this issue to resolve step 4 to run properly?

 

 

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...