Getting Data In

Splunk DB connect to Splunk

uagraw01
Motivator

Hello Splunkers!!

Splunk is receiving the data from my Qracle database table from DBconnect. All of the events are being created correctly when the query is run in the SQL editor. Some events are missing when they arrive in Splunk. What can be done if certain occurrences are missed? Please assist me in determining possible causes.

Note : My current "Max Rows to Retrieve" is on 10000.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Can you post your db input configuration? Add it into block </> (editor box).
0 Karma
Get Updates on the Splunk Community!

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...