All Apps and Add-ons

Splunk DB connect return result as empty for string/varchar fields.

AnthonyRRT
Engager

I have an issue where querying Oracle 9 DB using DB connect. All fields that are varchar returned as empty, but for numeric or date it is returning correcting. 

 

Say if I run on SQL explorer "Select sysdate from dual" or "select count(*) from table_A" I will get the expected result, but running "select transactionid from table_a;" it will return multiple rows  of empty data. 

 

And if I run "select sysdate, transactionid from table_a;" I will get sysdate correctly but transactionid field as empty. 

 

I try to added as input, but when I check the events all the varchar fields does not exists in the events.  Using "select sysdate, transactionid from table_a;", I can see sysdate in the event but not transactionid. 

 

if I run the query in SQL developer it is all working perfectly fine.

For other DB input I am using, I don't have this issue.

I have trying add the query as input, cast the varchar fields but nothing seems to work.

Just wonder if anyone has any ideas how could I work around this? 

 

Below is the information of DB and Splunk:

DB is Oracle - Version: 9.2.0.8.0
Splunk Version: 7.2.5

Current Application: Splunk DB Connect
App Version 3.1.3

Labels (1)

AnthonyRRT
Engager

Found a workaround, not sure why this happens but if I cast the varchar field to char it will work. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...