we have selected the rising column feature of DBX that allows Splunk to incrementally import new database records. But it’s not working and getting old logs into our Splunk aswell.
we need logs from the 01st March 2022 but we are receiving logs from the last year 2021.
select * from xxxxxxxxxxxxxxxSELECT * FROM your_tableWHERE LoginDt > ?ORDER BY LoginDt ASC
checkpoint value : 3/1/2022 00:00:00.000
If LoginDt field is not DateTime type field, the query will be sorted as text. This does not seem Splunk DBConnect problem.
You can test the result by replacing ? sign with checkpoing value.
SELECT * FROM your_tableWHERE LoginDt > '3/1/2022 00:00:00.000'ORDER BY LoginDt ASC
The best option is using an ID column if there is any incrementing numeric field, the lst option may be a DateTime field.