Getting Data In

DBX Rising Column Field Reverting to previously used Field Value after one query

sreed
New Member

I'm having an issue with DBX where I'm trying to change an existing input or create a new input (I've attempted both) to change the field I'm using for the rising column. I've been using a date/time field for rising column out of necessity but we recently added a proper rising column field to the table that I'd like to switch to.

The problem I'm running into is every time I switch to the new ID column from the EventDateTime column, the DBX input queries the data once with the new ID value and then appends the latest EventDateTime value into the rising column log. The ID field remains in the configuration but the input is now broken because the rising column value reverted.

2021-02-18 14_35_29-Window.png2021-02-18 14_35_29-Window.png

This happens whether or not I'm re-using the old Input or if I create a completely new input from scratch. I AM attempting to use the existing custom source and sourcetype information so I don't have to edit my 20+ dashboards and many more field extractions. If anyone has any thoughts on this I'd greatly appreciate the feedback!

 

Thanks,

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...