Splunk Search

DBConnect fetch not to consider latest value of rising column

pradeepkumarg
Influencer

The rising column I'm using is a time stamp and at times there are many records with the same value and if the fetch happens in the middle of those records, DBConnect is missing the rest of the records coming with the same value.

How can I limit the fetch not to consider the latest value so that all of them are fetched in the next run.

Example rising column value - dateUpdated - 2014-08-05 13:39:00.0

0 Karma
1 Solution

pradeepkumarg
Influencer

pradeepkumarg
Influencer

I found the answer mentioned in the below thread solves the purpose

http://answers.splunk.com/answers/68699/database-table-doesnt-have-rising-column-totally

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...