All Apps and Add-ons

Data is not being shown after configurint DB connect

jesusgalloEMC
Explorer

I created a new DB connect for Splunk it worked good so far using Windows authentication and the Splunk driver
Then I created the Identity and the Connection, all good there.
Afterwards on the DataLab the input is completed, I did the connection in the "Set SQL Query", catalog, schema, table and I execute the SQL and it works perfect, data is being shown.
then when i Click next to "Set properties".

I put the description the Application=Splunk DB Connect
Parameters i leave all by default except for the Execution frequency i put it to run every 5 minutes
metadata i select the Index and SourceType
but when i run the actual search in Splunk it doesnt work it doesnt show anything.
index=main sourcetype=sqldata
and nothing is shown.

Can anyone tell how to troubleshoot?
what frustrates me is that the SQL connection is retrieving results and no errors on the connection, i just dont know why in the Search the index and SourceType set are not showing results.

can any one tell what to look at or Troubleshoot?

Thank you very much!

ansif
Motivator

Check the below few things:

  • Change the time range of your search. (check with All Time)
  • Check whether you have created any custom index for this input.
  • Check which column you have given as time stamp.
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...