All,
We configured splunk to index data from a Oracle DataBase using Splunk DB Connect App .
Our database tables and data are very simple , and we are using free version of splunk .
Below are our observations :
Data Base Input configuration :
[InputType : Tail **
Rising Column : number type
Sourcetype : dbmon:kv
Splunk Index : default
Output format : Key-Value ]
When index interval was set to AUTO , splunk indexed the data (very few new rows )at a random speed . i.e, after few hours or sometimes even after a day .
When index interval is set to 60 sec - First , 10 new rows were indexed in 30 minutes .Then , for once , data (with 50 new rows ) was indexed exactly in 60 sec . After adding 150-200 new rows , indexing din't happen at all .
Now we set the interval to 2 sec and inserted just 3 new rows . No indexing happened .
We suspect it is because of the load on splunk server . Could anyone please tell whats the problem here .
Appreciate any advise on how to make splunk index database data quickly .
Please help !!
... View more