We upgraded the db connect to the new version 3 but now we are facing the issue of not being able to get data. Moreover the ORDER BY seems to be causing the issue.
We are trying to pull 1000-100000s of row per minute and not getting any success. The query works in the first place, as we are able to preview the data on Choose and Preview Table. As well as able to get data in Splunk itself before it breaks down on next attempt 😞
Did you have relevant logs to share? You can search index=_internal sourcetype=dbx_server
and probably add a condition with your input name to limit to only see the relevant events.
did you use a "?" as suggested here:
http://docs.splunk.com/Documentation/DBX/3.0.3/DeployDBX/Createandmanagedatabaseinputs
hope it helps
Yeah my query already has it.