Knowledge Management

How to configure Db connect to read new events only?

BcWilliams
Engager

I'm having an issue where db connect is reading the whole database every hour and also logging duplicate events instead of reading new events. So yes I have up to 10-20 of the same event logging into Splunk. Would adjusting the execution frequency solved this issue?

Labels (1)
0 Karma
1 Solution

PaulPanther
Builder

@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation

You have to choose Rising mode and then set the Rising column.

If you need further support just let me know.

View solution in original post

PaulPanther
Builder

@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation

You have to choose Rising mode and then set the Rising column.

If you need further support just let me know.

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...