Application:
Splunk db connect
Need:
Need to update a value into SQL table via Splunk dashboard
Query to INSERT a value into SQL table:
| dboutput type=insert database=MyDatabase table=MyTable notFound=insert fields=ColumnName as ColumnValue
| dboutput type=insert database=MyDatabase table=MyTable notFound=insert ColumnName1 as ColumnValue1 CoulmnName2 as CoulumnValue2
Received Error :
command="dboutput", com.splunk.util.csv.CSVException: No CSV input
Tried the above 2 queries , but getting the same Error Message for both
I have already made the database.conf settings. Have set the readonly permission to 'False'
What is the mistake i am making here, am i using the correct format for dboutput query ?
Kindly help.
I hope that helps.
| dboutput type=sql database=MyDatabase "INSERT INTO MyTable column, column values column, column"
Here is an actual search command I used and validated it worked:
index=main eventtype="wineventlog-security" | table event_id, EventCode | dboutput database=MSSQLSERVER type=sql "INSERT INTO processes (windows_event_id, windows_event_code) VALUES ($event_id$, $EventCode$)"
Hope it helps.
This was very helpful to me. Thanks!!
I hope that helps.
| dboutput type=sql database=MyDatabase "INSERT INTO MyTable column, column values column, column"