Knowledge Management

How to configure Db connect to read new events only?

BcWilliams
Engager

I'm having an issue where db connect is reading the whole database every hour and also logging duplicate events instead of reading new events. So yes I have up to 10-20 of the same event logging into Splunk. Would adjusting the execution frequency solved this issue?

Labels (1)
0 Karma
1 Solution

PaulPanther
Builder

@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation

You have to choose Rising mode and then set the Rising column.

If you need further support just let me know.

View solution in original post

PaulPanther
Builder

@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation

You have to choose Rising mode and then set the Rising column.

If you need further support just let me know.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...