Splunk Search

DB Connect & Refreshing

cpbridges
New Member

Hi! I am using the DB Connect app to successfully bring in a SQLite3 database. This database gets updated every 15 mins. How do I refresh the database and the searches every 15 mins too. Currently I am either deleting and readding the database or restarting splunk - which isn't ideal. Many thanks in advance! Chris

Tags (1)
0 Karma
1 Solution

vstolya
Explorer

Hope the following will help:
Database input params
Input Type = Tail
Rising Column = dbField
Interval = 15000

View solution in original post

0 Karma

vstolya
Explorer

They are in /splunk/etc/apps/dbx/local/inputs.conf
database.conf - contains database connections

0 Karma

vstolya
Explorer

Hope the following will help:
Database input params
Input Type = Tail
Rising Column = dbField
Interval = 15000

0 Karma

cpbridges
New Member

Ah, thanks! where is the database input params?
/splunk/etc/apps/dbx/local/database.conf?

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...