Splunk Enterprise

Why is dbxquery not fetching the large number of data from database?

Ashwini008
Builder

Hi,

I am using dbxquery to fetch the db data ,the db data is huge hence i am using maxrows=56406002.

But the query is keeping loading for 30-40 mins and later throws an error as below even though i am fetching only one year data

'Search auto-canceled'
'The search job has failed due to an error'

'| dbxquery connection=XXX query="SELECT DATE, ENDDATE, BEGDA, ENDDA FROM  PA2001 where BEGDA>=20160101 AND BEGDA<=20161231" maxrows=56406002
| streamstats count as SL_NO |table DATE ENDDATE BEGDA ENDDA SL_NO'
Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...