All Apps and Add-ons

How to change the Checkpoint Value in a Splunk DB Connect 2 input for the rising column?

kiran331
Builder

Hi all,

How to change the Checkpoint Value in a Splunk DB Connect 2 input for rising column?
Current Checkpoint value=2023-10-04 09:53:43.0, it's not indexing any events.

1 Solution

kbarker302
Communicator

Go to $SPLUNK_HOME/etc/apps/splunk_app_db_connect/defaults/inputs.conf, and look for tail_rising_column_checkpoint_value. You can either remove that line altogether or change the timestamp to some other value. Note that this may re-index records you may have already indexed, unless you delete them from Splunk first. If you don't see the checkpoint value under the default folder, then look under local. You may need to restart Splunk after updating inputs.conf.

View solution in original post

kbarker302
Communicator

Go to $SPLUNK_HOME/etc/apps/splunk_app_db_connect/defaults/inputs.conf, and look for tail_rising_column_checkpoint_value. You can either remove that line altogether or change the timestamp to some other value. Note that this may re-index records you may have already indexed, unless you delete them from Splunk first. If you don't see the checkpoint value under the default folder, then look under local. You may need to restart Splunk after updating inputs.conf.

kiran331
Builder

Its changing again once it ran.. How to solve this issue

0 Karma

kbarker302
Communicator

It always updates with the timestamp of the last record it indexed, so it knows where to pick up when new records are added to the database. Also, I just noticed that the timestamp in your example has 2023 for the year. If new records are added to your database with a year less than that (i.e. 2016) they won't get indexed.

0 Karma

kiran331
Builder

Is this the issue with query?

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...