Knowledge Management

How to configure Db connect to read new events only?

BcWilliams
Engager

I'm having an issue where db connect is reading the whole database every hour and also logging duplicate events instead of reading new events. So yes I have up to 10-20 of the same event logging into Splunk. Would adjusting the execution frequency solved this issue?

0 Karma
1 Solution

PaulPanther
Motivator

@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation

You have to choose Rising mode and then set the Rising column.

If you need further support just let me know.

View solution in original post

PaulPanther
Motivator

@BcWilliams Check the Input type of the DB input as described in Create and manage database inputs - Splunk Documentation

You have to choose Rising mode and then set the Rising column.

If you need further support just let me know.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...