All Apps and Add-ons

DB Connect input no longer refreshing index with data from database

splunknoob408
Explorer

Please pardon any incorrect terminology here as I try to explain the problem I am having. 🙂

I have a database that contains log information and I created a "rising" input in DB Connect with a 60 second refresh. The rising column is set to my timestamp field.

I was under the impression that this means every 60 seconds, splunk will hit my database and pull in all of the latest records since the last fetch. It also seemed to work fine for a day or so. However, today I noticed my dashboard hadn't updated, and the last data pulled from the DB was on 12/15.

I have no idea why it's not refreshing the data, so I am hoping that someone here can shed some light on possible misconfiguration on my part. Thank you!

0 Karma
1 Solution

splunknoob408
Explorer

I realized that the problem was with my search. I had forgotten that when I started to learn about indexes, I changed my approach to create an index for aggregating my shipping data from multiple database tables. It was indexing that all along, and my old source (for one reason or another) stopped updating. I'm not sure why that would happen, but once I replaced the source with "index=shipping" in my search, it ran as expected.

View solution in original post

0 Karma

splunknoob408
Explorer

I realized that the problem was with my search. I had forgotten that when I started to learn about indexes, I changed my approach to create an index for aggregating my shipping data from multiple database tables. It was indexing that all along, and my old source (for one reason or another) stopped updating. I'm not sure why that would happen, but once I replaced the source with "index=shipping" in my search, it ran as expected.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...