Splunk Search

Local database name

pehlke
Splunk Employee
Splunk Employee

Just commenting here because I'm not sure that the documentation is really clear on the point: when adding a local database like sqlite, the database name should be the fully qualified path to the database file.

Tags (1)
0 Karma

ziegfried
Influencer

Correct.

Alternatively you can place the SQLite file into $SPLUNK_HOME/var/dbx (you might need to create this directory) and name it as database_name.sqlitedb, then you can use "database_name" instead of the fully qualified path.

piebob
Splunk Employee
Splunk Employee

thanks for this information, the documentation has been updated to clarify:
http://docs.splunk.com/Documentation/DBX/1.0.8/DeployDBX/Addadatabaseconnection#Manage_database_conn...

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...