Splunk Search

Local database name

pehlke
Splunk Employee
Splunk Employee

Just commenting here because I'm not sure that the documentation is really clear on the point: when adding a local database like sqlite, the database name should be the fully qualified path to the database file.

Tags (1)
0 Karma

ziegfried
Influencer

Correct.

Alternatively you can place the SQLite file into $SPLUNK_HOME/var/dbx (you might need to create this directory) and name it as database_name.sqlitedb, then you can use "database_name" instead of the fully qualified path.

piebob
Splunk Employee
Splunk Employee

thanks for this information, the documentation has been updated to clarify:
http://docs.splunk.com/Documentation/DBX/1.0.8/DeployDBX/Addadatabaseconnection#Manage_database_conn...

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...