All Apps and Add-ons

Splunk DB Connect: Why is data being lost when connecting to a MSSQL server?

cpuppet
Path Finder

My Splunk DB Connect seems to have some data lost issue connecting to a MSSQL server where the DB is used as customer service loggings.
Has anyone face the same problem while tailing a datetime column and missing a few rows comparing data in Splunk and database?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This is why Splunk cautions against using timestamp/datetime as a rising column. Once DB Connect reads a set of rows, it asks for a new set consisting of rows with datetime column values greater than the value last read. Any rows written to the DB with the rising column value since the last read will be skipped.

Have you checked the datatime values of the lost rows?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...