Getting Data In

DB Connect Rising old logs

splunkcol
Contributor

 

Database connection via DB connect in rising mode

It was presented that logs stopped arriving for a range of 2 hours

If the configuration is in rising, it is understood that only new records are brought, and if there is no data in a time range, is it because the database does not have that information?

Because that is what I am going to answer to the client, that he check directly in the database if the data in that time range exists or does not exist

or should I check something else?

Labels (5)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, the use of a rising column means only new data will be read from the DB.  That presumes, of course, that the instance running DB Connect was running for those 2 hours and the DBX input was enabled.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, the use of a rising column means only new data will be read from the DB.  That presumes, of course, that the instance running DB Connect was running for those 2 hours and the DBX input was enabled.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...