All Apps and Add-ons

Splunk DB Connect: Why is data being lost when connecting to a MSSQL server?

cpuppet
Path Finder

My Splunk DB Connect seems to have some data lost issue connecting to a MSSQL server where the DB is used as customer service loggings.
Has anyone face the same problem while tailing a datetime column and missing a few rows comparing data in Splunk and database?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This is why Splunk cautions against using timestamp/datetime as a rising column. Once DB Connect reads a set of rows, it asks for a new set consisting of rows with datetime column values greater than the value last read. Any rows written to the DB with the rising column value since the last read will be skipped.

Have you checked the datatime values of the lost rows?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...