Hello fellow Splunkers,
I'm trying to connect new DB input, but I'm facing a small problem.
I've configured a rising column (time) and run my query from the "create new input" screen to make sure that I get no SQL errors (which I don't) and that I'm getting the data I wanted (which I do) but for some reason Splunk won't let me continue with the creation of the input.
The final part of my query looks like this:
"WHERE time>? AND field1='1'
ORDER BY time ASC"
When trying to create this input, Splunk shows an error saying that my query doesn't
accept checkpoint.
My guess is that the "AND" messes-up the expected syntax.
Does anyone have an idea how to work around the problem?
Thanks