Knowledge Management

How to configure Db connect to read new events only?

BcWilliams
Engager

I'm having an issue where db connect is reading the whole database every hour and also logging duplicate events instead of reading new events. So yes I have up to 10-20 of the same event logging into Splunk. Would adjusting the execution frequency solved this issue?

0 Karma
1 Solution

PaulPanther
Motivator

@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation

You have to choose Rising mode and then set the Rising column.

If you need further support just let me know.

View solution in original post

PaulPanther
Motivator

@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation

You have to choose Rising mode and then set the Rising column.

If you need further support just let me know.

Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...