Splunk Search

Splunk DB Connect - Tail only from latest value in database?

falkyre
Explorer

Still trying to get the tail monitor working. It seems that once it's enabled and scheduled, then executed, the first run takes ~ 4 hours to get the information from the database. Is there any way to force the tail to start at the last record in the database? Or at least have the ability to provide a starting point based on the rising value column being used?

Tags (1)
1 Solution
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...