Splunk Enterprise

Why is dbxquery not fetching the large number of data from database?

Ashwini008
Builder

Hi,

I am using dbxquery to fetch the db data ,the db data is huge hence i am using maxrows=56406002.

But the query is keeping loading for 30-40 mins and later throws an error as below even though i am fetching only one year data

'Search auto-canceled'
'The search job has failed due to an error'

'| dbxquery connection=XXX query="SELECT DATE, ENDDATE, BEGDA, ENDDA FROM  PA2001 where BEGDA>=20160101 AND BEGDA<=20161231" maxrows=56406002
| streamstats count as SL_NO |table DATE ENDDATE BEGDA ENDDA SL_NO'
Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...