Hi, Initially I was using rising column as datetime but there was some data loss.. i.e. not every data was dumping to Splunk from SQL. So I changed rising column to Id(int) and its working fine on one of my TST environment. But when I am doing the same for Prod, after every run my checkpoint value change to datetime instead of Id although in rising column its showing Id. And due to that no data is coming to Splunk. Please help.
... View more
@thambisetty I found the solution for it.. There should be integer incremented value for rising column that Spunk understand properly.. I also changed the rising column to it Id (int incremented value in DB) instead of datetime and its working fine..
... View more
Hi, I am fetching data for Splunk from Sql database. I found some of the rows are missing.. I am checking it for complete day with below splunk query index="myavista_events" sourcetype="myavista:sitecore:sqldb" | stats count and for the same period I am checking it SQL with sql query and found lots of diff in count.. In SQL data count is more as compare to Splunk.. SO some data is missing in Splunk. I am fetching the data at every 5 min interval from DB.. And I tried to check the count in each fetch with below Splunk query.. index=_internal ServerName "format_hec_success_count" This is giving count like format_hec_success_count=3365 But this number is also not matching with sql query for same timespan.. Please suggest how can I get the complete sql data in splunk...
... View more