All Apps and Add-ons

Splunk DB Connect 2: Why are we getting no results in pivot when using a dbxquery query?

pieterms
New Member

We use the following database query in search mode.

|dbxquery query="SELECT%20*%20FROM%20%60app%60.%60order%60" connection="sqldb" maxrows=100 

When we want to make a pivot for these results, the "count of event object" stays on 0. When I press on the "count of event object" link, the following search qeury will be displayed on screen in search mode again.

(dbxquery query="SELECT%20*%20FROM%20%60app%60.%60order%60" connection="sqldb")  

The pipe character is disappeared so the query doesn't work anymore. How do I solve this problem so we can make pivot visualizations for these queries?

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

that data will have to be indexed to be used with pivot.

0 Karma

pieterms
New Member

How can I index this data?

I think this data already indexed via the Splunk DB Connect 2 - DB Input. The meta data is set in this plugin.

0 Karma

karthikeyan_mac
New Member

I have created the DB Input. Is there another way to index the data?

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...