All Apps and Add-ons

Data is not being shown after configurint DB connect

jesusgalloEMC
Explorer

I created a new DB connect for Splunk it worked good so far using Windows authentication and the Splunk driver
Then I created the Identity and the Connection, all good there.
Afterwards on the DataLab the input is completed, I did the connection in the "Set SQL Query", catalog, schema, table and I execute the SQL and it works perfect, data is being shown.
then when i Click next to "Set properties".

I put the description the Application=Splunk DB Connect
Parameters i leave all by default except for the Execution frequency i put it to run every 5 minutes
metadata i select the Index and SourceType
but when i run the actual search in Splunk it doesnt work it doesnt show anything.
index=main sourcetype=sqldata
and nothing is shown.

Can anyone tell how to troubleshoot?
what frustrates me is that the SQL connection is retrieving results and no errors on the connection, i just dont know why in the Search the index and SourceType set are not showing results.

can any one tell what to look at or Troubleshoot?

Thank you very much!

ansif
Motivator

Check the below few things:

  • Change the time range of your search. (check with All Time)
  • Check whether you have created any custom index for this input.
  • Check which column you have given as time stamp.
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...