I'm having an issue where db connect is reading the whole database every hour and also logging duplicate events instead of reading new events. So yes I have up to 10-20 of the same event logging into Splunk. Would adjusting the execution frequency solved this issue?
@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation
You have to choose Rising mode and then set the Rising column.
If you need further support just let me know.
@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation
You have to choose Rising mode and then set the Rising column.
If you need further support just let me know.