Splunk Enterprise

DB Connect indexing query results as single item


We recently setup a new Splunk system and were in the process of migrating some existing DBX based database inputs over to the new system when we found that the new platform is now treating the entire result set of the query as a single item when indexing the data, instead of treating every record in the result set as a separate indexed item.

Is there a configuration file that needs to be edited to rectify this, as we're copying the available settings in the actual DBX db input screen exactly.

Any help would be appreciated.

Tags (2)
0 Karma

Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...

Announcing Our Splunk MVPs

We are excited to announce the first cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...