Hello,
I connected my Oracle database with Splunk using db connect, but it does not recover the data.
Someone can help me please.
Are you running queries against your database? Connecting the database just allows you to then run queries against it and put the results of those queries into Splunk.
If I understand correctly you want to tell me that I can not perform SPL requests on this data??
for example, I run this query to see if it has recovered the data from Oracle but it shows me that type CSV returned sourcetype=*|stats count by sourcetype as shown in the following figure.
Did you actually ran the SQL query first to store the data in an index or trying to run searches in database using SPL?
I'm trying to run SPL queries on this data, I'm trying to put find event, but no event is found