I set up a connection, "medicinedb", to serve as an output from Splunk to an SQL server. For testing, I set this up to run every minute. I don't see any activity and any errors when I run this output.
I cannot get Splunk to update records in this third party system.
I have verified that:
- The Splunk data source is returning records
- I am mapping data
- I can read from medicinedb
- I can make updates using basic SQL queries to medicinedb
I can also verify that this works:
| from savedsearch:"Medicine - Canonical"
| dbxoutput output=medicinedb
You can view screenshots here:
https://www.dropbox.com/sh/ess43vxnkndftqk/AACmeiekTgZgzp6xLjpyQCBPa?dl=0
Thanks in advance for any suggestions.