All Apps and Add-ons

Using timestamp as "rising column" in DBconnect v3: Missing IN or OUT parameter at index:: 1

dailv1808
Path Finder

Hi Splunker,

I tried to use timestamp as "rising column" but it didnt work.

Please help!!!

 

image_2021_01_27T10_24_56_213Z.png

when input type = Rising

 

image_2021_01_27T10_25_21_960Z.png

 

 

 

 

 

 

Labels (1)
0 Karma

dailv1808
Path Finder

Need help!!

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @dailv1808,

Can you please try formatting TXTIME as epoch format? 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @dailv1808,

After changing to Rising mode you have to execute query once. Then you should update your query with where clause. Most probably error reason is checkpoint "?" variable has no value yet. 

If that does not work you can update checkpoint value with a valid time value from your results.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

dailv1808
Path Finder

Hi @scelikok 

Thanks for you reply, it doesn't work. When changing to Rising mode, Splunk need filter the rising column with a WHERE statement and sort the results with ORDER BY. "java.sql.SQLException: Invalid column index"

 

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...