Splunk Search

Local database name

pehlke
Splunk Employee
Splunk Employee

Just commenting here because I'm not sure that the documentation is really clear on the point: when adding a local database like sqlite, the database name should be the fully qualified path to the database file.

Tags (1)
0 Karma

ziegfried
Influencer

Correct.

Alternatively you can place the SQLite file into $SPLUNK_HOME/var/dbx (you might need to create this directory) and name it as database_name.sqlitedb, then you can use "database_name" instead of the fully qualified path.

piebob
Splunk Employee
Splunk Employee

thanks for this information, the documentation has been updated to clarify:
http://docs.splunk.com/Documentation/DBX/1.0.8/DeployDBX/Addadatabaseconnection#Manage_database_conn...

0 Karma
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...