I have configured Output connection in Splunk DB Connect, which takes search results of inputlookup of CSV file (76k entries) and send it to a MySQL table in another machine every hr in Upsert mode.
The MySQL table is configured as InnoDB engine, and table setup look as follows:
fields1 varchar(200)
fields2 varchar(200)
fields3 varchar(30)
fields4 varchar(20000)
The table received only 49897 records from Splunk, which remains constant. I'm confused why the table didn't receive all the data from Splunk. Any pointers? Thanks!
I was able to fix this issue:
Edit /opt/splunk/etc/system/local/limits.conf, add below lines and restart Splunk.
[default]
max_mem_usage_mb = 400
[searchresults]
maxresultrows = 100000
I was able to fix this issue:
Edit /opt/splunk/etc/system/local/limits.conf, add below lines and restart Splunk.
[default]
max_mem_usage_mb = 400
[searchresults]
maxresultrows = 100000