All Apps and Add-ons

Splunk DB Connect rising input creation problem

nembela
Path Finder

Hi,

I have the following problem with rising input creation. If I try to add the following query as a rising input, I receive an error:

SELECT *
FROM DIARY
WHERE DIARY_DATE > ?
AND TABLE_ID = 3
ORDER BY DIARY_DATE ASC

But the following query works:

SELECT *
FROM DIARY
WHERE DIARY_DATE > ?
ORDER BY DIARY_DATE ASC

"Step 4" fails when I click "next" on the "New input" screen, however the query runs fine. db_connect.PNG

According to the documentationit is permitted to use complex WHERE clauses:

"Use other advanced SQL features in the WHERE clause—for example a CASE statement."

Do you have any idea what went wrong here?

 

Thanks,

László

 

 

Labels (2)
Tags (2)
0 Karma
1 Solution

nembela
Path Finder

It turned out that it was a bug in DB connect (DBX-5327) that was fixed in 3.4.2

View solution in original post

0 Karma

nembela
Path Finder

It turned out that it was a bug in DB connect (DBX-5327) that was fixed in 3.4.2

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Under the heading of "dumb things to try that just might work" try swapping the order of the where clause.

SELECT *
FROM DIARY
WHERE TABLE_ID = 3
AND DIARY_DATE > ?
ORDER BY DIARY_DATE ASC
---
If this reply helps you, Karma would be appreciated.
0 Karma

nembela
Path Finder

Thanks for the suggestion. I tried to exchange the conditions but it did not help. The result was the same.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...