Knowledge Management

How to configure Db connect to read new events only?

BcWilliams
Engager

I'm having an issue where db connect is reading the whole database every hour and also logging duplicate events instead of reading new events. So yes I have up to 10-20 of the same event logging into Splunk. Would adjusting the execution frequency solved this issue?

Labels (1)
0 Karma
1 Solution

PaulPanther
Builder

@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation

You have to choose Rising mode and then set the Rising column.

If you need further support just let me know.

View solution in original post

PaulPanther
Builder

@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation

You have to choose Rising mode and then set the Rising column.

If you need further support just let me know.

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...