All Apps and Add-ons

Using timestamp as "rising column" in DBconnect v3: Missing IN or OUT parameter at index:: 1

dailv1808
Path Finder

Hi Splunker,

I tried to use timestamp as "rising column" but it didnt work.

Please help!!!

 

image_2021_01_27T10_24_56_213Z.png

when input type = Rising

 

image_2021_01_27T10_25_21_960Z.png

 

 

 

 

 

 

Labels (1)
0 Karma

dailv1808
Path Finder

Need help!!

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @dailv1808,

Can you please try formatting TXTIME as epoch format? 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @dailv1808,

After changing to Rising mode you have to execute query once. Then you should update your query with where clause. Most probably error reason is checkpoint "?" variable has no value yet. 

If that does not work you can update checkpoint value with a valid time value from your results.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

dailv1808
Path Finder

Hi @scelikok 

Thanks for you reply, it doesn't work. When changing to Rising mode, Splunk need filter the rising column with a WHERE statement and sort the results with ORDER BY. "java.sql.SQLException: Invalid column index"

 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...