Splunk Search

unable to view the events with data lab input

sagar0907
Engager

i have created a data lab input. the query is configured to fetch the data in batch manner which runs every 30 mins. when i run the Query with DBXQUERY i am able to see the output/events also in the 1st stage of data lab input creation i could see the records. but when the input was configured i tried to search for the events , i could not find any events. i tried with all the pre-defined indexes as well as with the customized index (updated the required files in splunk ), still i am unable to fetch the data.
we are required to achieve this because most of the dashboards are dependent on DB and we can not build each dashboard with DBXQUERY.
kindly help me to resolve this.
thanks in Advance

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...