Getting Data In

How do I set up Splunk DB Connect so I only get new log information every time I do a query instead of pulling the whole

dennislevine
New Member

How do I set up Splunk DB Connect so I only get new log information every time I do a query instead of pulling the whole database each time?

I've got the connection working and I'm getting data in, but every time the input runs it pulls the entire database again instead of just pulling in the newest data. How do I limit what it pulls?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Use a Rising input.  This is where DBX keeps track of the last value seen for a specific field so subsequent queries can fetch newer values.

See https://docs.splunk.com/Documentation/DBX/3.18.1/DeployDBX/Createandmanagedatabaseinputs#Choose_inpu... for details.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...