Getting Data In

DBconnect cron schedule behavior

vin_ven27
Explorer

I used DBconnect to pull data from the database in every 1min *(cron: * /1 * * * *). I would like to ask if this schedule is simple as:

#1 - Run every e.g. 10:00, then 10:01 then 10:02 and so on... or?

#2 - Run every e.g. 10:00 (wait until the job done) example 10:00:35 so the job will run at 10:01:35. 

Please advise as we encountering missed of data when we tried the #1.  Thanks

Tags (2)
0 Karma

vin_ven27
Explorer

thanks for a quick response @venkatasri 
Actually that is our first schedule setup which is every 5mins it's just so happen that the client want a data updated of what will be the possible minimum time. So we change to 1min cron schedule and the SQL set as batch and get only past 1min of the data using updated time column. For us to resolve the missing data our work around is to get 90secs past data instead of 1min in SQL and the cron still 1min. But not sure though if this work this out. Any idea?/suggestion?

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@vin_ven27  Yes that's every min you can verify same here - Crontab.guru - The cron schedule expression editor

Every min seems bit aggressive have you tried changing the schedule to every 5 mins at least, there could be other issues as well for missing logs.

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@vin_ven27  batch mode actually duplicates your data hence chances of missing your data is very slim. Did you check the DBConnect logs?

The time column that you are using sometimes transaction commits with delay in DB.  you have to check if there are delays to commit in DB, your DBA can help.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...