I am using DBCOnnect 2 on a HeavyForwarder, in local resource pool mode, with a rising column input - the rising column is an integer and I also tried using a timestamp column as a rising column.
When comparing the results in the DB and the results in Splunk, records are missing in splunk, as if splunk hasn't indexed or read them at all.
The DB is SQL server. The values are missing both for timestamp rising column and for integer rising column.
Neither the integer column nor the timestamp column have null values or get updated.
What could be the cause of the problem?
In the log, see ConfPathMapper: /opt/splunk/etc/apps/splunk_app_db_connect/local: Refused forced reload of inputs.conf: outstanding write
But not sure this is related
Is the rising column an integer that is auto generated by the table such as ROWID, etc?